Rendered at 18:35:22 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
jhallenworld 23 hours ago [-]
I have a new LG TV, holy moly what a terrible user experience. Out of the box it requires you to create an LG account. PITA, but OK. Except I was supposed to set the location first, instead I set it after. So now you have the problem that you can not log into LG.com using my own email (even from a web browser) because it says: "incorrect country". I contacted their tech support about this, the only fix is to switch back the country code on the TV (to US_Other), then delete the account from there, then set country code to US, then create it again. OMG. I guess there is no fix if TV breaks before you do this..or if you forget what the original country code was. You are then forced to use a different email for any future LG product. I notice that all LG smart products use the same phone app, BTW.
Also, I bought an LG soundbar to go along with it. You would think they would work well together. The soundbar sounds fine, but the synchronization drifts over time. I've tried optical, LG's enhanced optical (allows you to control the volume) and HDMI eARC. In theory optical in PCM mode works better, but then you give up the volume control. Why should an end customer know about any of this?
Lip sync is a simple problem to solve (timing pulses and code slipping will always work) and they have failed at it.
Also: their remote sucks (compared with Roku).
Anyway, so no respect for LG.
krelian 22 hours ago [-]
I recently had to replace my 5 year old LG OLED with a new one. The UX has been downgraded to an abysmal level. It's just unfathomable how such simple UI widgets take multiple seconds to load and how can QA say "ok, that's good enough". And don't get me started about the shoehorned "AI". A feature that, if you forget to turn it off will randomly interrupt whatever you're watching to talk to you in an almost unintelligible metallic voice. The build quality of the remote control also took a nose dive. Image quality is great but the same as my old TV, no advancements there.
nostrademons 22 hours ago [-]
I had an LG TV for work because my team developed some of the software on it. Similar experience - it got progressively worse (including the software my team developed, which in true Google fashion was deprioritized, discontinued, team laid off, and left to rot without anyone bothering to tell LG that it was no longer being maintained) until by the time I left that team it was nearly unusable as a "smart" TV and all I did was run Netflix and Disney+ on it. Then my kid broke it with a well-placed whack of a plastic sword.
Would definitely not buy with my own money. I actually really like a lot of LG's other appliances (we have a washer, dryer, and dual ovens from them that are great), but for a TV, I just want a dumb screen that I can hook an HDMI cable to and run off a computer.
mschuster91 22 hours ago [-]
> but for a TV, I just want a dumb screen that I can hook an HDMI cable to and run off a computer.
Look into Digital Signage displays. You pay a brickload more money but get (much) higher quality in return.
nicwolff 45 minutes ago [-]
My 55" LG Wallpaper signage display is pretty much perfect – it just has HDMI in from an Apple TV and never bothers me. But, it takes ~10 seconds to turn on after a signal is detected, since it was never meant to be turned off!
Uvix 16 hours ago [-]
I haven't found digital signage displays with the same brightness for HDR content, or variable refresh rate support.
reaperducer 21 hours ago [-]
You pay a brickload more money but get (much) higher quality in return.
Not anymore. The last time I checked B&H they weren't very much more expensive than comparable "smart" televisions.
Laurel1234 21 hours ago [-]
Also it's really important to tell every guest in your home that the TV is recording everything they say or you'll be violating wiretapping laws, as per the EULA.
jhallenworld 21 hours ago [-]
The main point of selecting the country seems to be getting you to consent to the country specific EULA. There's also region-based content management, but it's secondary at this point.
> i. CONSENT REQUIREMENT: You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws. If anyone does not consent, you should disable the microphone or voice features in the settings. LGE disclaims any liability for your failure to obtain such consent or provide such notification
Genuinely one of the most batshit insane things I've seen a company pull, their entire board should be liquidated along with their parents for failing to raise them.
jhallenworld 59 minutes ago [-]
So actually, this TV is for an AIR B&B I rent out. I guess technically I need to add their stupid EULA to my rental agreement.
temporallobe 3 hours ago [-]
Not sure why optical is a problem in 2026! I have a 2014 Samsung plasma dumb-TV and pipe the optical straight to my old (2002-ish) Yamaha receiver with absolutely zero issues (no sync drifting) and it sounds like a dream compared to the soundbar on my other TV.
yumraj 21 hours ago [-]
Does it not work if you don’t connect to Internet and not create an account?
reaperducer 21 hours ago [-]
I have a new LG TV, holy moly what a terrible user experience.
My LG TV doesn't support Bluetooth, and it's only maybe eight years old.
Instead of simply connecting to Bluetooth headphones, you're supposed to put some LG app on your smart phone, then sync that via wifi with another app on the TV, then connect your smart phone to the headphones via Bluetooth.
Instead, I just watch less TV and will not purchase LG in the future.
(And let's stop pretending that "LG" stands for "Life's Good" like it says on the power-on splash screen. It means "Lucky Goldstar." If life was good, I'd be able to use Bluetooth headphones.)
alterom 13 hours ago [-]
Well it doesn't sound like you're having much luck with that setup, or would award it any gold stars, so there's that.
GJim 9 hours ago [-]
> LG TV, holy moly what a terrible user experience.
I was put off buying one as, here in Blighty, all LG TV's come with a built in Amazon Alexa which if you don't enable it, nags you every time you turn on the TV (talk about doing the bare minimum to comply with the GDPR!).
jacobgold 23 hours ago [-]
US residential proxies are the bane of the internet. They're the major source of social media manipulation and spam.
Services can dramatically reduce abuse by blocking entire IP ranges based on country of origin, organization, or type (hosting providers). But a company can't block US residential IPs if it would also cut off many of their real customers.
The US government (probably the NSA) should be cracking down hard on US residential proxy networks. They're a genuine national security threat, actual data/identity loss of American citizens, act as infra for foreign covert influence campaigns, botnets used in hacking/DoS attacks, etc.
Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)
inigyou 7 hours ago [-]
Counterpoint: IP range blocking is the bane of the internet, and I'm glad I can get around it by buying residential proxies. They cause very little problem to anyone except for the companies that think they can be the tzar of who gets to view certain information. The most unethical component is that the user often didn't consent to installing the proxy (which causes no problems for him) but this can be resolved and some people voluntarily install proxies for money.
nemomarx 3 hours ago [-]
how's it avoid causing problems for the user? it's using their Internet. imagine if they had data caps or so on and you're downloading through that proxy - that's basically taking his money, right?
rnd0 45 minutes ago [-]
Alternate take; deliberately broken moderation systems and perverse incentives are the biggest source of social media manipulation.
Fix social media, and leave the consumers alone.
Also the firehose of spam will continue regardless of what you do on the consumer end.
pudgywalsh 22 hours ago [-]
My major sources of spam traffic are Chinese and Indian residential and mobile IP blocks. So there's that.
Second, everybody screamed loudly when they were cracking down on file sharing traffic. You're saying spying on the citizens is ok when it's for this little reason over here, but not this one over there. It doesn't track.
Not to mention most ISP abuse mailboxes are automated these days because they are flooded with LLM-generated reports from "security" grifters.
The tech industry flooding the market with countless IoS (Internet of Shit) devices didn't help. This has moved way beyond accidentally installing spyware on your PC. People are intentionally bugging their homes with these devices.
I understand the FCC is trying to crack down on this stuff - starting with routers - but of course that gets pushback too. You can't win.
jacobgold 22 hours ago [-]
There's no spying required. The NSA and ISPs can find open proxies through infiltration and report them to (e.g. abuse@comcast.com), then Comcast simply has to act on it robustly.
ISPs already deal with abuse reports like this, the system just isn't being operated comptently.
SoftTalker 22 hours ago [-]
What is Comcast going to do about it? Shut off a paying customer? Not likely.
jacobgold 18 hours ago [-]
Voluntarily, maybe not, but we can make it a legal requirement.
inigyou 7 hours ago [-]
Because that worked out so well with file sharing
jacobgold 5 hours ago [-]
Because this is exactly like file sharing...
inigyou 4 hours ago [-]
The ways you are asking the government to mutilate the internet are quite similar to the ways the media industries asked the government to mutilate the internet.
jacobgold 2 hours ago [-]
What I'm calling for is exactly how things are already supposed to work.
The US government should already be infiltrating hacker groups and identifying infected American computers. Internet providers should be informing customers that hackers have compromised their devices.
Characterizing this as "mutilating the internet" is ridiculous.
pudgywalsh 22 hours ago [-]
What are you talking about? These are not open proxies.
You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?
They are intentionally made hard to detect and access is sold to the highest bidder.
Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.
jacobgold 22 hours ago [-]
> These are not open proxies.
Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.
> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.
This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.
pudgywalsh 19 hours ago [-]
Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?
Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?
16 hours ago [-]
jacobgold 16 hours ago [-]
> Ok but these proxies almost certainly reverse-tunnel. How do you prove a customer is hosting one?
Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.
You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.
But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.
wyldberry 23 hours ago [-]
I'm glad someone else is saying this. Entire companies exist (that do a great job at it) that primarily surface this information in the form of "threat intelligence" for companies to make risk decisions based off of.
negura 12 hours ago [-]
gosh, thanks for sharing your US national security concerns. as a former Googler. straight out of San Francisco. the world's epicentre of "win-win" tech innovations
> But a company can't block US residential IPs if it would also cut off many of their real customers.
since when do companies care whether they cut off real customers? i've been paying for residential proxies for everyday internet browsing for nearly 6 months. because it's the only way to pass the captcha service of another famous company headquartered in San Francisco
throwawayqqq11 9 hours ago [-]
In a not so far dystopian future, we might be thankful for any bit of anonymity we get. I am waiting for the day my ISP detects and blocks my tor/vpn traffic, as GP suggested. You think politicians/regulators wouldnt go so far to "protect children"?
dpoloncsak 23 hours ago [-]
> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)
Is there incentive for them to? If anything, you might be paying extra for the data use and not even know it, right? They would lose money
jacobgold 22 hours ago [-]
It may actually be costing them money through higher peak usage (requiring more capacity). I'm not sure but either way the government should have a role if market incentives aren't sufficient.
justcool393 15 hours ago [-]
yeah no, this isn't a good take imo. we already have way too much of ISPs doing bad things to internet shaping and random governmental overreach (from state govts no less!) on domains and such.
if someone wants to knowingly host a proxy they should. stuffing it along with other apps is shady and if LG wants to disallow those apps from their store than w/e but like we don't need governmental stuff encroaching on this stuff. if LG wants to do moderation on those apps than whatever.
there was a lot of fighting over this stuff back in the early 2010s because the alternative was effectively a balkanized corponet.
smart TVs, by virtue of being devices you can write apps for, have morphed into more general purpose computing devices and keeping it as open as it can be is important. the backsliding from stuff like Android has been horrible for the ecosystem and that shouldn't be normalized, let alone as a legal requirement geez
some_random 23 hours ago [-]
A crackdown would probably be an FBI responsibility, the NSA is not a law enforcement agency and absolutely does not have the authority.
jacobgold 22 hours ago [-]
In terms of law enforcement, sure. But what we really need is competent white hat hackers doing battle with the black hats.
Even if no one goes to jail, the NSA could make residential proxies much harder to operate in the US simply by detecting them and reporting them to ISPs. It would be good for ISPs to then validate the reports properly, give warnings, etc.
inigyou 7 hours ago [-]
A lot of residential proxy networks don't let you access financial and government websites because that would create an actual national security risk and get them shut down. So, given that, what is the actionable complaint?
jacobgold 5 hours ago [-]
- Actual data and identity loss of American citizens.
- Malware that can record video and audio from infected devices.
- Infrastructure for foreign covert influence campaigns.
- Botnets used in hacking and DoS attacks.
inigyou 4 hours ago [-]
So that would also apply to, like, Xiaomi, right? Or basically any foreign code you run?
wnevets 22 hours ago [-]
> Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)
Does having TLS everywhere make this much harder?
jacobgold 22 hours ago [-]
Not sure how it would? Because the bad actors are remotely instructing infected computers/devices to make HTTP/TLS requests for them, so they appear totally normal to the other side.
Retr0id 22 hours ago [-]
In a hypothetical world where using TLS was abnormal, you could monitor the content of whatever the bots are doing for suspicious activity. And if they chose to use TLS anyway, the mere presence of of TLS could be considered suspicious.
Back in the real world, you can also passively fingerprint TLS handshakes to characterise the client device. Most of these proxy networks masquerade as "normal" clients, but if the type and variety of device fingerprints for an IP suddenly changes, that's a signal too.
inigyou 7 hours ago [-]
It's not a crime to buy a new device and log it in to your WiFi.
Retr0id 6 hours ago [-]
Of course not, but if someone buys 1000 new devices and rotates devices with each request, it might be worth sending them an email like "hey did you mean to be doing that?"
Retr0id 22 hours ago [-]
Until DoH and ECH are commonplace, DNS lookups and SNI probably leak enough for statistical analysis.
paulddraper 21 hours ago [-]
DNS and SNI are usually not encrypted.
cute_boi 16 hours ago [-]
And it is source of major scam. NSA can simply sign up residential proxy and start banning each hop. But, I guess they aren't interested.
12_throw_away 2 days ago [-]
42% of the apps on LG's platform have these quasi-malware SDKs in them? Seems kinda bad, whether it's due to negligence or just pure incompetence? You'd think there might be legal consequences for a corporation that lets their app store turn into a malware delivery system?
drnick1 2 days ago [-]
It's not "quasi-malware," it is malware.
b3orn 1 days ago [-]
15 years ago people would've called it spyware.
TeMPOraL 1 days ago [-]
20 years ago people would've called it a trojan horse.
But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.
blagie 23 hours ago [-]
> But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.
I don't think you've read GDPR. In Europe (at least my part), *every* organization has a GDPR policy you need to agree to. Your child's school. Summer camps. Etc. Most are also conservative and reasonable.
What's broken is the GDPR popup with a dozen "legitimate interest" toggles for spying on you.
matthewmacleod 12 hours ago [-]
That was exactly the point OP was making.
ge96 23 hours ago [-]
Funny some you can't say no, so I'm like alright guess I'm not going in
tosti 1 days ago [-]
There were no cookie popups 20 years ago.
_joel 1 days ago [-]
Err, there were, prepare to feel old "Cookie consent pop-ups first started appearing following the adoption of the ePrivacy Directive in 2002" 25 years!
reactordev 1 days ago [-]
I beg to differ, there absolutely was cookie popups. We also had popup windows, popup ads, java applets that melted your cpu, and browsers with no grid. Oh, and we had Shockwave and Flash…
ledoge 1 days ago [-]
I think they meant that the use of cookies for analytics/tracking, which is what triggers the popup requirement, would have been considered malicious.
TeMPOraL 1 days ago [-]
Indeed.
efreak 10 hours ago [-]
Some browsers would individually request you approve each cookie s website set. This is a feature of the browser itself that the website is unable to control. Lynx still has this option, I believe.
amelius 1 days ago [-]
Yes, let's put the Overton window back where it used to be.
inigyou 7 hours ago [-]
... If it was spying—,it isn't
Manuel_D 19 hours ago [-]
My understanding is that these apps' TOS explains that by using the app you consent to having third party traffic routed through your device. For example [1] the Hola VPN's free users agree to let third party traffic get routed through their networks. Now, how closely users actually read the TOS is a different story, but it's arguably not malware on the grounds that users are, at least on paper, informed and agree to this behavior.
Nope, still malware. Arguing that people can technically read the TOS is (maliciously?) ignoring the social contract that most of us live by (i.e. don't trick people and screw them).
inigyou 7 hours ago [-]
My understanding of malware is that it must cause some problem for the user.
einsteinx2 6 hours ago [-]
Slowing down your internet connection due to using your bandwidth without your knowledge, getting blocked by websites due to malicious traffic from your IP address, extra annoying captchas due to the same. Those were just the first 3 things off the top of my head.
inigyou 6 hours ago [-]
Got plenty of bandwidth, sites block you regardless, you get captchas regardless. Plus, IP addresses rotate once a day so you're just as likely to get someone else's bad reputation anyway.
To sue them you'd have to show some actual, concrete harm. For example you contact a site that is blocking you and they tell you it's due to a certain request and you trace that request to the proxy.
Cthulhu_ 1 days ago [-]
It's all above board though, as you, the user, agreed to the terms & conditions for installing said app.
This won't change unless governments create and enforce laws.
account42 1 days ago [-]
Terms and conditions are not the get out of consumer protections free card that you think it is.
ethbr1 1 days ago [-]
They are, unless governments actually crack down.
A lack of enforcement actions has caused situations like this.
Why would LG do better when it's cheaper to not?
soraminazuki 1 days ago [-]
Are there laws against clauses in the T&Cs that allow companies to arbitrarily change the said T&Cs? Are there laws against clauses that prevents consumers from suing companies? Unless there are, T&Cs absolutely are the get out of jail free card both on paper and in the real world.
xethos 1 days ago [-]
I mostly agree, but it's the lack of enforcement that's the Get out of Jail Free card, not the T&C
wren6991 20 hours ago [-]
> It's all above board though, as you, the user, agreed to the terms & conditions for installing said app.
I have an LG TV, about 6 years old now. For a while it was connected to the internet. Every time I turned it on, after a ~20s delay, it would pop up asking me to install an update and I would press RIGHT + OK to select the "No" button because it worked fine and previous updates just made it slower, added ads etc.
Eventually, the remote dropped the button press for RIGHT, and just got the OK. Or maybe I just pressed the buttons too fast -- the interface is laggy and I'd developed muscle memory. This started the software update with no way to cancel from the UI. Once it updated, it made me accept a new EULA just to continue using the TV in the way I already used it (which was mostly as an HDMI display). There was no way to even get to the settings dialog to perform a factory reset without accepting the EULA. The device was held hostage until I said "Accept."
This is the level of consent implied by accepting the EULA on a TV: none. It's bullshit. Computers should never have been put in TVs, and a smart TV should never be connected to the internet.
inigyou 7 hours ago [-]
Then you took it back to the store for a refund, right?
quotemstr 1 days ago [-]
It is, though. Why should I not be able to agree, with sufficiently informed consent, to route traffic through a connection I operate via a computer I own using software I've chosen of my own free will to install?
What's the difference between running a Tor exit node and a "residential proxy" except optics?
Look: I'm 100% for banning secret proxies that hide from the user, but stopping people knowingly and voluntarily running these proxies is a violation of fundamental software freedom tenets.
ozlikethewizard 1 days ago [-]
The difference is the user. Your average smart TV user doesn't know what a residential proxy is, hell who's installing/playing the games but children? Consumer regulation to protect consumers from a knowledge disparity that leads to uninformed consent isn't a bad thing imo.
quotemstr 1 days ago [-]
[flagged]
beamy 1 days ago [-]
Isn’t this like arguing we shouldn’t have food standards because people should be free to decide what they put in their bodies?
Sure, in principle that’s true.
But in practice, is it really fair to expect everyone to understand the health risks of every possible ingredient?
Likewise here, is it fair to expect the average consumer to understand what it means to host a residential proxy? Or even what a residential proxy is?
soraminazuki 1 days ago [-]
The industry has proved again and again and again over the past two decades that surveillance, manipulation, and profiteering is all they care about, and the public is wising up to this fact. "We're screwing you clueless people for your own sake" is no longer effective as a thought terminating cliche and can only create stronger animosity towards the industry.
inigyou 7 hours ago [-]
Note that residential proxies are not a surveillance technology, but an anti-surveillance technology. They defeat IP-address-based surveillance.
ozlikethewizard 1 days ago [-]
Did I say that? Regulate the companies that produce the products not the products themselves.
ethbr1 1 days ago [-]
[dead]
account42 1 days ago [-]
We're not talking about people voluntarily installing proxies, we're talking about proxies piggy backing on apps that are marketed for an entirely different purpose.
quotemstr 1 days ago [-]
The article is clear that LG is talking about banning all proxies, even voluntarily installed ones. A smart TV is a computer. Why should the owner of a computer not be allowed to run any program he wants?
amiga386 1 days ago [-]
That is not the case.
The article is quite clear that LG runs an "app store" where 42% of the "apps" likely contain residential proxies, and LG is going to make its "app store" developers stop doing that. From TFA:
> “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”
This says nothing about your own software installed on the TV, should that be possible.
But even if you ran your own software on your TV, would you run a proxy service? Given you already have a residential ISP, you wouldn't need to hook your TV up to a botnet and buy residental ISP access for your scrapers via your own, or other unwitting suckers', TVs.
Your hypothetical of wanting to run a Tor exit node is silly. Most Tor exit node operators run them knowingly on dedicated hardware, usually in a datacentre, not their own home, and prepare themselves legally for when they inevitably get emails from law enforcement, or worse, raided. You'd almost certainly firewall the destinations it can reach, you wouldn't let it have access to your own network, and you wouldn't run it on your TV.
fc417fc802 1 days ago [-]
It very much is the case. Your own quote contradicts you. A smart tv is definitely a computer (one of the selling points is literally that it runs arbitrary apps) and LG is declaring that this "is not an intended use for LG smart TVs" and banning it.
There is certainly a conversation to be had regarding consumer protection laws, the nature of an appliance, and the trade-offs thereof but this is not that conversation and I don't think you engaged in good faith with the comment you replied to.
amiga386 1 days ago [-]
I don't think a bunch of dodgy app vendors who put TVs in botnets is who you should be going to bat for.
Read it again: "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform"
It is working with developers it has a contractual relationship with, and has approved their apps for download from its "app store" -- this one: https://gb.lgappstv.com/main/tvapp
...where 42% seem to be ADDING THE TV TO A BOTNET.
LG TVs form a substantial botnet, and LG didn't appear to know or care.
This is not about a person using their own TV to add it to a botnet (WHY WOULD THEY DO THAT?), it's about "app developers" knowing that LG is lax in checking what "apps" do, and putting out trojan horse apps that, if the TV user installs them, adds the TV to a botnet, without the TV owner's knowledge.
This is entirely orthogonal to "can I run my own choice of software on my LG TV?", which is not addressed in the article at all.
HDBaseT 15 hours ago [-]
I have trouble believing LG "didn't appear to know" almost 50% of applications on their store were effectively spyware.
It takes one look at the App Store on these TV to know all these apps are sketchy...
wmf 22 hours ago [-]
Some people do run Tailscale proxies in their home, and an always-on device like a TV is a good place to run it.
efreak 10 hours ago [-]
Why would your TV always be on? My TV is only on when I'm using it.
inigyou 7 hours ago [-]
Do you mean the screen is on or the processor is on? If it's plugged in, the processor is on.
amiga386 7 hours ago [-]
[flagged]
windward 1 days ago [-]
It all comes back to this. I pay for the network, I'm liable for it: I decide what comes through it.
JumpCrisscross 1 days ago [-]
> You'd think there might be legal consequences
I own an airgapped LG TV. Does anyone actually want to go class action/mass arb?
tjoff 1 days ago [-]
Airgapped is harder than you might think. If your TV finds an open network (neigbours?) it will use that one. And it is only a matter of time before they have cellular capabilities too.
lelandfe 1 days ago [-]
> If your TV finds an open network (neigbours?) it will use that one
I looked into this last year while researching TVs and couldn’t find anything to substantiate it.
JumpCrisscross 1 days ago [-]
> Airgapped is harder than you might think
Probably. The LG TV I have doesn't have cellular, but does have a removeable Wifi/Bluetooth module [1]. You have to disconnect a ribbon, unscrew the module and then pop it out.
Sometimes those "modules" are just the antenna, and the Wifi is quite capable of connecting with no antenna at all.
dzdt 23 hours ago [-]
Make it a tinfoil hat :-)
SoftTalker 22 hours ago [-]
Maybe 10 years ago. Very few homes have an open network today, ISPs all ship their routers with random passwords and/or force the customer to create a WiFi password during setup.
18 hours ago [-]
Mindwipe 22 hours ago [-]
When was the last time you saw a completely open residential wifi access point in the wild?
This seems a little like worrying about getting Dodo poisoning.
HeyLaughingBoy 4 hours ago [-]
Mine up until a few months ago. Didn't really care because you'd have to stop literally in front of my house to access it. And living on a street with only about 4 properties, that would merit a visit from me asking why you're parked in front of my house.
JumpCrisscross 22 hours ago [-]
> When was the last time you saw a completely open residential wifi access point in the wild?
I have family who get frustrated with their home Wi-fi and about every other year conclude the solution is to unsecure the connection.
SoftTalker 22 hours ago [-]
I'm not sure Comcast would even let me do that today, though I haven't tried. I gave up running my own home router and WiFi a few years ago, they just made it too much of a PITA.
tjoff 21 hours ago [-]
maybe not residential, but if you are close to a coffee shop or bar or anything else that offers it...
Mindwipe 3 hours ago [-]
I genuinely don't recall the last time I saw one of those that didn't require me to at least go to a registration page to accept the terms and conditions in order to actually transmit any traffic.
kmeisthax 22 hours ago [-]
Aah yes, the ol' "Emergency Wi-Fi Connection" Nintendo uses to make really scary anti-piracy screens where they dial 911 and call the cops on you playing a pirated version of New Super Mario Bros U.
LG's behavior isn't fine, but their monitors don't install crapware on Linux.
TeMPOraL 2 days ago [-]
The monitors aren't installing anything. That headline was a lie.
It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.
delta_p_delta_x 1 days ago [-]
> It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs
This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality or some graphical front end to the driver's configuration knobs.
LG then abused that feature to provide adware. Now, there are millions of hardware vendors. One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Sometimes one actually wants the app that comes with the device, like AMD's and NVIDIA's configuration trays.
Even so, I fully expect that after this debacle MS will disable this stuff. There is precedent for this. Synaptics/ELAN/Alps touchpad tray applications largely disappeared after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs. Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
account42 1 days ago [-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time
Why not? Microsoft isn't a struggling startup. They can afford to do just that.
HeyLaughingBoy 4 hours ago [-]
IIRC, at least 15 years ago, that's exactly what they did. They published a tool suite that your driver should pass before submission because otherwise it would fail when they got to it. I think the submissions were fully automated by that time.
rincebrain 1 days ago [-]
Because at scale, that doesn't work, I think, even money no object, because it's a task that requires a lot of domain knowledge, but also is monotonous and offers little in the way of satisfaction or looking good on your resume, so the candidates you're trying to hire aren't very junior, and also are not going to like the work.
Aaargh20318 1 days ago [-]
If you can’t offer a feature like this in a secure manner then you shouldn’t offer the feature at all.
account42 1 days ago [-]
Why not? "At scale" is not an argument on its own. This is something where scale helps you because the number of different hardware you need to support is independent from the size of your customer base.
And if you really can't act responsibly "at scale" then you shouldn't be allowed that scale.
Cthulhu_ 1 days ago [-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Maybe not, but LG has violated this trust and should therefore be either fined or severely restricted by Microsoft. Banning will likely cause more problems than solutions, but they shouldn't get away with this.
Adware was a huge problem during the Windows XP era, can't believe it's coming back now through Microsoft's official channels.
Also I doubt there's actually millions of hardware vendors. But that aside, Microsoft has a duty to vet everything that they offer through their channels. If it's too expensive for them to do, do like Apple did and have those that want to make use of their distribution network (and trust) pay them.
maccard 1 days ago [-]
I agree with you on the precedent
> after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs.
There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.
> Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
The peripherals still need the addons though; I have ASUS armory crate, Corsair iCue and MSI center for my Motherboard, cooler and GPU respectively. They all suck.
doikor 1 days ago [-]
> There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.
The latest Dell trackpads are quite bad. Price or the product being premium or not unfortunately does not tell you if it will have a good trackpad or not. And it changes over time (Dell XPS used to have really good trackpads)
Basically you have to go to a store and try or find reviews that actually pay attention to this.
delta_p_delta_x 1 days ago [-]
> There’s still a world of difference between a MacBook touchpad and a windows one
Oddly I've found otherwise (Dell Precision notebook from 2021, and Surface Laptop). It might be macOS's animations and smoothing interfering here, but I've found that my Windows touchpads are much more responsive, especially when swiping between desktops.
> The peripherals still need the addons though
Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.
maccard 1 days ago [-]
On the trackpads - I only ever use my MacBook as a single screen device, so the experience may be different. A long time ago I used it with an external monitor and the experience was very poor compared to windows.
> Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.
Yeah, I commented on the McAfee LG thread but the stuff that comes bundled with hardware is embarassing. I don’t know how Razer, Logitech, nvidia, MSI, asus, etc get away with it. The stuff is awful, even their “good” software. I work in games and a few years ago the biggest correlation we had between unexplained crashes/performance problems in the wild was users having MSI Afterburner installed. Users thought it did great things and fixed a bunch of games but it absolutely thrashed everything we worked very hard to do and caused no end of issues doing so.
TeMPOraL 1 days ago [-]
> Yeah, I commented on the McAfee LG thread but the stuff that comes bundled with hardware is embarassing. I don’t know how Razer, Logitech, nvidia, MSI, asus, etc get away with it. The stuff is awful, even their “good” software.
Well, this is the whole market on its own. It's entrepreneurship. No different than every web SaaS startup trying to capture some entry-level piece of computer use and then constrain it so it interoperates only with their "net of trusted partners".
They get away with it because everyone is happy and making money - the users, notably, are not part of the group here, and have no voice. The users are resources to be exploited. Same as on the web, and on most markets these days.
chronogram 1 days ago [-]
What part of Afterburner caused issues? I have it installed to undervolt an old GPU but not actively running.
Other overlay apps like discord https://www.reddit.com/r/discordapp/comments/1jncrlc/new_ove... have similar issues - the way they work is by drive hooks and drawing over the application; depending on how close you are to the limit and how the game loop is coded this can very easily (and often does) cause micro stuttering, and in cases like discord causes massive performance problems regularly.
TeMPOraL 1 days ago [-]
My point is not to shift the blame to Microsoft; it's primarily LG that's at fault here.
My point here is simply that it's not the monitor that is installing this. Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.
themaninthedark 1 days ago [-]
This is a primary LG fault, however I would say that Microsoft also has a fair bit of blame here.
They are downloading and installing something without the users consent.
It's nice to have drivers work without any intervention, same with "helper software" but along side the ease of use they also took on the responsibility.
If I download some random .exe from the net; I have to confirm that I want to run it, sometimes I even have to right click and unblock it to allow it to run, because it is "untrusted".
Their signature key, their auto-run system, everything done for ease of use means they own this.
Otherwise what does "trusted" mean?
tosti 1 days ago [-]
Yes, and it's only possible thanks but no thanks to MicroSlop.
And it's not like MS is too poor to do anything useful for their customers. They just don't want to unless the cost-benefit analysis pans out in their favor. The customer is worth as much as their wallet.
windward 1 days ago [-]
>Even so, I fully expect that after this debacle MS will disable this stuff.
Isn't the debacle over? MS know about this by now. What's stopping them from killing it today?
A late resolution is barely a resolution at all. None of this functionality needs new Windows features.
denkmoon 1 days ago [-]
I can only imagine the meetings at microsoft HQ where they all sat around a table and crossed their fingers and hoped that vendors would act in the spirit of their design.
21asdffdsa12 1 days ago [-]
The commercial software landscape more and more reminds me of a civil war torn town. Everyone shooting at everyone, a dark forest through and through
noir_lord 1 days ago [-]
It’s more a tragedy of the commons, we are the commons.
Aaargh20318 1 days ago [-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
If you're going to allow 3rd parties to install software on potentially billions of computers with far reaching privileges then you better have something in place other than 'just trust me bro'.
dTal 23 hours ago [-]
Why's that? "Just trust me bro" is the security model of all closed source, proprietary software. OMG, the program with secret source code is doing shady stuff? I'm shocked - shocked!
Hard to get worked up over "3rd parties" when even 1st parties cheerfully stomp all over the interests of their users. That ship sailed, caught fire, and sank to the bottom of the ocean the day Candy Crush appeared in the goddamned Start menu.
benj111 1 days ago [-]
If they aren't willing to vet, they should at least be keeping the update minimal. Ie no 'sidecar' apps.
Self signing a driver should mean just that, not a driver, and a load of other things we feel like foisting on the user.
Half the reason I moved to Linux is because I just wanted to print something without getting a load of advertising from a printer company.
petesergeant 1 days ago [-]
> One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Apple seem to do a pretty decent job of just that
delta_p_delta_x 1 days ago [-]
The situation is very different on Macs. Apple control almost the entire hardware stack of the machines that macOS runs on. They make it an absolute pain in the neck to run any application not blessed by attestation. This attestation server is also frequently offline. They've also made it very difficult to write things like filesystem drivers, having completely pulled that functionality from more recent versions of macOS. In fact, if I recall correctly one cannot ship a third-party kext on more recent Macs, especially ARM ones. As such, hackintoshing has basically vanished as a hobby.
At least on Windows, the most you get is a scare screen saying 'this app is from an unidentified developer'. I know what I'd rather have.
wat10000 23 hours ago [-]
At least when I plug a monitor into my Mac, it doesn't install anything. And somehow it still works despite this.
petesergeant 1 days ago [-]
> At least on Windows, the most you get is a scare screen
Well that and side-loaded LG adware
felooboolooomba 1 days ago [-]
> That headline was a lie.
Kinda agree but let's call it "misinformed" or something, instead of a lie.
fauigerzigerk 1 days ago [-]
I would say it's neither a lie nor misinformed. It 's a punchier headline that can be justified by what the user experiences. The user connects a monitor which causes ads to appear. The rest of this Rube Goldberg contraption is a mere detail.
TeMPOraL 1 days ago [-]
Those details are the only thing that matter. Without them, all you have is superstition.
fauigerzigerk 1 days ago [-]
I disagree. It matters that LG makes ads appear on their customers' screens as a deterministic consequence of connecting one of their monitors. It's not superstition.
Of course the details are important on some level. But that doesn't make everything else not matter and it doesn't turn an incomplete explanation into a lie.
TeMPOraL 1 days ago [-]
That's my point: it's not a consequence of connecting a monitor. An external element is making it look like such.
This difference tells you that, for example, you cannot fix the problem by fixing the monitor, because the problem does not exist in hardware. It's actually entirely external to the hardware you own, because it exists entirely "in the cloud" (i.e. on MS and LG servers).
fauigerzigerk 1 days ago [-]
No you're wrong. It absolutely is a consequence of connecting an LG monitor. Connecting an LG monitor triggers a chain of events that deterministically and deliberately cause these ads to be shown.
The hardware alone is not sufficient for this to happen, but if you were to modify or "fix" the monitor (specifically its firmware) so that it no longer identifies as an LG monitor, then it would no longer cause these ads to be shown.
In other words, if A causes B and B causes C then it is correct to say that A causes C.
account42 1 days ago [-]
The headline isn't a lie, even if you can technically nitpick it.
The manufacturer implemented choices to deliberately install the software when the monitors are connected. The mechanism is not important to why this is outrageous.
TeMPOraL 1 days ago [-]
I disagree, the mechanism is the only important thing. Everything else is storytelling and superstition.
drnick1 2 days ago [-]
Another win for the Linux security model (software installed and updated manually from vetted repos only).
gblargg 2 days ago [-]
Wait, you're saying a monitor can just advertise a URL over the video connection for its driver and then Windows will blindly install it, without user confirmation? I thought that LG had submitted these "drivers" (adware) to Microsoft and they approved it.
Sophira 1 days ago [-]
As far as I'm aware, the monitor does not transmit a URL. Windows is looking at the hardware's vendor and device IDs and using those to look up and download the "drivers" that LG has stated are for that device.
stkdump 2 days ago [-]
I think the point is that:
1. Yes Windows must have "approved" the drivers
2. Windows Update runs automatically and not (usually) manually
3. Automatic update can't even be disabled, only manually postponed a bit
At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior.
To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later.
I believe you register your device with Microsoft so Windows can automatically obtain and install drivers for them when they are plugged in.
What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.
debugnik 1 days ago [-]
This is actually a feature of the .inf by design, an AddSoftware directive. It can even link to apps from the store instead of bundling them with the driver. This is designed to install settings panels like the ones for GPUs.
I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.
ssl-3 2 days ago [-]
Eh? No.
It's just a device attached to a computer.
But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades.
Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)
gblargg 1 days ago [-]
> Eh? No.
That's what I thought. It is vetted software, just like on Linux. Microsoft just doesn't care if it shows ads.
ssl-3 1 days ago [-]
That's an excellent and terrific point. In this way, the dichotomy between Windows and Linux can be as if they're just two sides of the same "vetted" coin.
ChocolateGod 1 days ago [-]
> software installed and updated manually from vetted repos only
So something most desktop Linux users don't do.
preg_match 22 hours ago [-]
I would say 95%+ do just this. The Debian, Ubuntu, and even Fedora repos are very large and include all the software you could ever want. And then flathub takes the rest.
It’s really only arch with the AUR and some others where completely untrusted packages are used. This is legitimately a better model than what windows does, although Microsoft has been trying to change this with winget.
15 hours ago [-]
graemep 1 days ago [-]
Virtually all desktop Linux users do. The biggest exception is AUR as its not vetted.
windward 1 days ago [-]
'desktop Linux' is a term used when the majority of Linux users don't support your argument.
benj111 1 days ago [-]
Are you disputing that the repos are vetted or that users use them???
voidUpdate 1 days ago [-]
sudo dkpg -i FileYouDownloadedFromAnywhere.deb
mDyJzDPmBdG 1 days ago [-]
Let's be real, in most cases it is:
curl -s script.random-guy.net | sh
It is such glaring security hole that there was an old submission about filling such install script with `sleep` commands and detecting it on server side, to send different versions for downloading (and reviewing) and for actual direct execution.
very very stupid yes, and there are some other high profile softwares encouraging this brainrot, but, still not most.
anyone doing this should really take a very very big look in the mirror
preg_match 22 hours ago [-]
Almost never occurs as the repos contain a ton of software.
iso1631 1 days ago [-]
most of my machines use unnatended-upgrades
Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows
Surely Windows Update is a vetted repo as much as arch or debian
preg_match 22 hours ago [-]
There is one major difference: those install under your users. I haven’t seen a windows installer that didn’t require admin. Some older Linux apps require sudo. They don’t need to do that anymore, not for a while. We have xdg standards of where to install stuff in a users home directory.
vel0city 15 hours ago [-]
Tons of Windows apps these days install into user's AppData these days. Its common for installers to ask "Install for everyone or just me".
preg_match 2 hours ago [-]
The last time I used Windows seriously, which was Windows 10, this was not the case. If that's changed then great. But we need to acknowledge that Windows software install is changing to become more Linux-ified. With package managers and repos out of the box.
Clearly the Linux model is more secure, and Microsoft knows it. It's a good idea for Microsoft to take inspiration here. It's only a matter of time before they do containerization too, ala Flatpak. The biggest hurdle to that is Windows doesn't have native containers and the entire container ecosystem is build around Linux.
If Microsoft wanted my advice, which they don't, I think it would cost less at this point to just make Windows a Linux distro. Wine is already better at running older Windows software than Windows. Just expand Wine a bit, add in acceleration where it doesn't already exist, and boom you're done. Nobody would even notice.
And maybe then Windows on ARM wouldn't suck so much.
vel0city 1 hours ago [-]
> The last time I used Windows seriously, which was Windows 10, this was not the case.
Apps like Chrome and Spotify have been doing it for almost 20 years, since they made their Windows apps back in 2008. Python updated their installer to install to the user profile in 2015 with version 3.5.0. VSCode started doing it in 2018. Discord did it at launch in 2015. Zoom and Teams and Slack do it and have for a long time. Its been a pretty common pattern for a long time.
> Windows doesn't have native containers
Windows supports Windows containers natively and has supported Windows containers for a decade.
> maybe then Windows on ARM wouldn't suck so much.
Windows on Arm these days really isn't bad. It definitely sucked a lot several years ago with tons of compatibility issues (along the timeframe you said you last used it seriously), but they've made massive improvements since.
drnick1 1 days ago [-]
> Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -"
I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.
iso1631 9 hours ago [-]
== Docker ==
Docker provides a convenience script at https://get.docker.com/ to install Docker into development environments non-interactively.
Paste that in the macOS Terminal, a Linux shell or WSL. The script explains what it will do and then pauses before it does it. Read about other installation options.
== k3s ==
K3s provides an installation script that is a convenient way to install it as a service on systemd or openrc based systems. This script is available at https://get.k3s.io. To install K3s using this method, just run:
These scripts have lines like
> abort "Need sudo access on macOS (e.g. the user ${USER} needs to be an Administrator)!"
> # --- use sudo if we are not already root ---
zen928 19 hours ago [-]
> the expectation is that you deploy them in isolated user accounts or containers.
Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?
lostmsu 1 days ago [-]
Nah, install.exe must be signed by a certificate authority or you get 10 prompts, and they do revoke certificates.
krige 2 days ago [-]
Surely you mean Linux security model (not relevant enough to be targeted by big tech)?
trelane 1 days ago [-]
Famously, the Linux kernel does not have a stable ABI for drivers. As a result, by far the majority of drivers are in-tree, maintained by the kernel folks as part of the kernel.
The Linux approach has the downside of not having the drivers if a vendor has not been working with the kernel community before launch (or for those who haven't upgraded to a kernel that has the driver, e.g. a LTS release).
On the other hand, the driver is maintained by kernel developers, not created by the hardware developer who is not getting paid after they sell the device. This helps avoid abandoned / vulnerable drivers, or having the hardware dev search for... alternative revenue streams, as in this case.
dns_snek 2 days ago [-]
It's not a weakness that they targeted and exploited, it's a feature that was purposefully implemented by Microsoft.
krige 1 days ago [-]
If you're trying to say that Microsoft implemented a method of delivering specifically malware executables to every PC, I've got a bridge to sell to you.
Let's not diminish LG's part in all this.
dns_snek 10 hours ago [-]
No, what I'm saying is that Linux isn't safer simply because "it's not relevant enough to be targeted", it's safer because it doesn't offer mechanisms which could be abused to do this.
Nobody is diminishing LG's blame, LG is guilty of installing malware, and Microsoft is guilty of being grossly negligent and facilitating it. Microsoft implemented this feature knowing that it would eventually be abused for something like this, and it's bad enough to be indistinguishable from malice.
delta_p_delta_x 1 days ago [-]
> Another win for the Linux security model
I swear, OSs have become sports teams.
Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage.
There have been so many zero-click local privilege escalation CVEs I've lost track.
AUR is an effectively unmoderated user repo. It’s not Arch Linux’s core repository, nor is it enabled by default or indeed even possible to use without manual downloads from outside the package manager.
benj111 1 days ago [-]
There's still a security there though.
You have confidence you are actually downloading the same foo as everyone else. And if there were an issue there would be pushback. Not so if you get some random exe from warez.com
Yes it isn't perfect, it's still a lot better than windows land.
dns_snek 10 hours ago [-]
> Linux's 'security model’ has plenty of holes.
Implementation bugs are not holes in the security model. Linux has plenty of those, as does Windows.
Windows security model trusts, downloads, and immediately executes arbitrary software when a new untrusted device is plugged in, without asking the user.
opan 1 days ago [-]
I think you can probably find a better example, even if less recent. The AUR is unofficial and not properly vetted in the same way as the actual Arch repos, Debian repos, etc.
meta-level 2 days ago [-]
yet?
I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting.
And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.
Gigachad 2 days ago [-]
The LG scandal specifically relies on the fact windows will auto install OEM crapware as soon as you plug it in. No other OS does that.
rconti 2 days ago [-]
Huh? What does WebOS have to do with windows?
smackeyacky 1 days ago [-]
LG monitors not TVs
ahartmetz 2 days ago [-]
"Fortunately", agent Poettering is on the case, implementing remote attestation for Linux so we can all be secure. Barf.
A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.
mikepurvis 2 days ago [-]
I'm mostly very happy with my LG C4 as a home theatre centerpiece, and I did have it online so that I could use the apps for YouTube and Jellyfin. However, the lack of support for modern 4k rips (HEVC+DTS) ended up being a dealbreaker and I finally ditched the built in software for a fire stick instead.
No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.
kakacik 1 days ago [-]
There is always android VLC app to decode anything, you just need enough power in chipset to handle that. Not perfect, had some quirks unseen on desktop VLC but generally fine.
But yeah external stick is much safer solution, then even tvs like TLC are a great brand.
tosti 1 days ago [-]
I had a TCL TV unrelated to the programming language, and the ghosting was awful.
You need to hook something up to a network, and another device would have similar risks.
Setting up a sandboxed VPC or auditing traffic is beyond the means of the average TV owner.
timc3 1 days ago [-]
Apple TV is the usual recommendation.
qq66 1 days ago [-]
> and another device would have similar risks
Do you think an Apple TV and a Walmart special TV have same risks? I don't. I give the Apple device my network credentials and the TV never sees them.
coldtea 1 days ago [-]
>You need to hook something up to a network, and another device would have similar risks.
Another device might not give the free reign for all shitty malware like they do. Apple TV for one wouldn't.
account42 1 days ago [-]
> Want to stream Netflix? Disney+? Hulu?
No thanks, I prefer owning my media in a way that corporations can't just take it away whenever they feel like and where I can use (open source) players of my choosing.
pornel 1 days ago [-]
The problem is that the LG company went full-spyware. It's not a mere risk, they turned hostile on their customers.
mlrtime 1 days ago [-]
You have 3 replies all saying the same thing, install a ATV...
But the replies are missing the point that most people aren't techies and won't go do this. They go to big box store, buy the tv, ask if it has netflix, done.
They won't (and shouldn't need to) install a ATV.
michaelchisari 2 days ago [-]
Never once had a problem with an LG because I've never given it internet access. A trustworthy set top box handles everything instead. Concerned that might not be an option in the future.
jmward01 2 days ago [-]
That is my problem. What can you trust anymore? Is there an appliance out there that can do the basics and not be a malware gateway?
mapt 2 days ago [-]
Smart TVs replaced dumb TVs not out of consumer demand, but out of subsidy from commercial databrokers and streaming services. Despite adding $100 of hardware they were priced $100 cheaper.
throw0101a 1 days ago [-]
> Smart TVs replaced dumb TVs not out of consumer demand […]
The consumer demand was/is for cheaper, and data mining is how OEMs got there. The general public got what they want, and OEMs got to keep their margins: "win-win".
It's the same thing with (US?) airlines: people wanted cheaper, and that's what was offered and they chose.
vablings 1 days ago [-]
Faustian barging, the worst part is people are simple unaware of the dealings
lodovic 2 days ago [-]
I'm always wondering how hard it would be to just remove the hardware for spying. Just keep enough hardware to make it a dumb panel, remove the webos logic boards, wifi antenna, etc.
modo_mario 1 days ago [-]
Is there still any specific brand known for dumb tv's that features the quality and 'non smart' options of the smart variants?
throw0101a 1 days ago [-]
Many OEMs have "commercial" / "corporate" displays that may be applicable:
Consumers will happily sell their data for a $100 discount. Hell they'll waste 20 minutes watching adverts to save $1.
jddj 1 days ago [-]
You could give it a vpn to a public cloud provider so that even if they run residential proxies they still get a dirty vps IP.
Admittedly this doesn't stop the presumed screenshotting and microphone use and worse
gblargg 2 days ago [-]
LG now installs adware when you merely connect one of their monitors to a Windows PC.
CivBase 2 days ago [-]
Stop buying LG TVs.
smcleod 2 days ago [-]
Unfortunately they make arguably the best OLEDs and webOS is pretty decent to use (especially compared to the terrible OS that Samsung and Sony run). I think the best thing people can do is update their firmware then disconnect it from the internet. Using an AppleTV or similar provides a better experience than any TVs built in apps anyway.
cosmic_cheese 2 days ago [-]
I don’t ever use their “smart” functionality (that’s what my Apple TV is for) but I’ve never had any issues with the Google TV (Android) build that Sony ships. It doesn’t nag me about being kept offline, is reasonably fast, and doesn’t even show its home screen unless I specifically summon it, so it checks my boxes.
mey 2 days ago [-]
How important is "the best" OLED vs the second best or 100th best OLED? I am personally ok not buying the bleeding edge to not get malware onto my OS.
notatoad 2 days ago [-]
reasonably important, if you're never connecting your lg tv to any network, and just connecting it to an AppleTV or something and letting HDMI-CEC control it so you never even see their OS.
StumpChunkman 2 days ago [-]
Exactly this. And with an Apple TV 4K Ethernet, you've got a bonus Thread border router for smart home devices. I actually didn't even realize that initially, but was very pleased when I found IKEAs latest round of Matter over Thread devices paired nicely with it and my existing Home Assistant + Hue setup.
eproxus 1 days ago [-]
And if you install Tailscale you can even use it as an exit node to surf from home when you're traveling.
drnick1 2 days ago [-]
I would suggest a mini-PC running Linux and Plasma Bigscreen instead of an AppleTV if you want something 100% private and user-controlled.
notatoad 1 days ago [-]
my priority for a TV isn't privacy or user control, it's minimizing annoyance. and appletv, roku, or similar streaming boxes delivers that best.
przmk 1 days ago [-]
Unless you're using streaming services like Netflix, in which case you're stuck with 720p because of widevine.
N19PEDL2 2 days ago [-]
Do you recommend any specific distro for this?
drnick1 1 days ago [-]
Arch or Fedora, because you want a very recent KDE version.
theplumber 2 days ago [-]
If you care about malware you do not plug it into the internet. I think windows computers are pretty mallwareish as well or at least spyware. People who buy Oled buy them because they care about PQ.
smcleod 1 days ago [-]
If you care about home cinema it's important. There's a pretty big jump down. You can look up the specs and reviews of the C and G series from LG. Anecdotally quite a few times when people see my 7 year old LG C9 I've had them ask if it was some new expensive TV as they are so impressed with the picture.
2 days ago [-]
globular-toast 2 days ago [-]
Exactly. If you get the best today it'll be the second best tomorrow anyway. Absolute position is undetectable, you can only perceive change. Use that to your advantage and stay off the treadmill.
smcleod 1 days ago [-]
7 years into my C9 and it never fails to impress.
globular-toast 1 days ago [-]
Exactly. I could probably get a 10 year old panel and be happy with it.
altairprime 2 days ago [-]
2nd best, not. 100th, better to get a great LCD than a junk OLED?
Bud 2 days ago [-]
[dead]
jedberg 2 days ago [-]
I haven’t looked recently but last I checked Samsung made the best panels. Has that changed recently?
dodslaser 2 days ago [-]
Samsung is good, except:
- No Dolby Vision support, only HDR10+
- Issues with judder/micro stutter
- History of nerfing TVs via OTA updates
- HDMI ports randomly failing
- Bad HDMI-CEC implementation
- Selling completely different panel generations under the exact same model names.
mDyJzDPmBdG 1 days ago [-]
Also: Samsung thinks "your" TV is perfect place for them to display their ads.
nvme0n1p1 2 days ago [-]
Samsung scored highest on https://www.rtings.com/ for my criteria, and I'm happy with the purchase. I didn't connect it to the network, of course. (I had to stop my handyman from connecting it and he seemed to think I was crazy for insisting.)
lostlogin 2 days ago [-]
I installed a Pihole and set an edge router to direct any port 53 traffic that wasn’t from the Pihole, to the Pihole.
That made a Samsung behave a little better. But giving it no network access is better.
ahartmetz 2 days ago [-]
"I work in software. I have seen things you people wouldn't believe. Attack ships on fire off the shoulder of Orion. I watched C-beams glitter in the dark near the Tannhäuser Gate..."
Their panels are often over-saturated with that fake HDR like look, similar to their phones.
ahartmetz 2 days ago [-]
Most screens come with "showroom settings" out of the box. You need to configure them to something more neutral once and then it's fine.
smcleod 2 days ago [-]
I'm aware of that setting, but this is the Samsung baseline. The panels they export for OEMs / other manufacturers don't seem to have the same hyper saturation. Even just standing next to someone using a Samsung phone or tablet you can often spot it straight away we know you what to look for.
ahartmetz 2 days ago [-]
Even phones have screen settings these days (much less detailed than monitors). On my Motorola phone w/ OLED screen, I turned off "vibrant colors" or something like that. Maybe the people you saw didn't bother or liked it. Maybe there is something that can't be turned off, who knows. I only have semi-regular experience with an older (and non OLED) Samsung tablet which seems fine.
TeMPOraL 1 days ago [-]
Over saturated HDR is a good default in times when all TV shows only use various shades of pitch black.
PowerElectronix 2 days ago [-]
That goes away if you set them in filmaker mode.
PowerElectronix 2 days ago [-]
No, qd-oled is still best, LG is closing the gap with tandem oled but is still the second best panel tech.
mlrtime 1 days ago [-]
Samsung is worse, their OS is horrendous. LG allows local control fairly well and has Home Assistant support.
Samsung is a complete mess, now charging $5/month to use smarthings with no local control. I'll never buy Samsung.
pjmlp 2 days ago [-]
Have to agree, WebOS is much better than Android TV OS, with ads on the dashboard.
Gigachad 2 days ago [-]
As long as you keep it off the internet. Otherwise it’s absolute loaded with adverts everywhere.
pjmlp 2 days ago [-]
Not the 2020 version I have, it has a suggested shows row from the apps I have already installed, which makes sense.
Android TV even has ads for Disney and Apple, which I never installed.
Angostura 1 days ago [-]
I have a 2026 LG, attached to the internet - absolutely no ads. You need to tweak the settings
Leonard_of_Q 2 days ago [-]
You can replace the Android TV launcher with an alternative like Projectivy [1] to get rid of whatever nonsense the stock launcher tries to push. Add Flicky [2] to address F-Droid and you've got a nuisance-free Android TV.
Thanks, however is kind of the problem, it shouldn't be a thing in first place.
windward 1 days ago [-]
>I think the best thing people can do is update their firmware then disconnect it from the internet.
We don't need treats this badly.
Yizahi 1 days ago [-]
I thought webOS was pretty decent initially. But LG never provided even a single major update to my TV in a decade, so that just about cancels any possible benefits from the faster code. I'm using Chromecast for several years now, bypassing and ignoring webOS completely. But the initial idea was nice, all those years ago.
smcleod 1 days ago [-]
Really? I've had many updates over the 7 years since my c9 was released, still getting them as recent as earlier this year I think.
Yizahi 1 days ago [-]
Just to clarify - my LG TV is old (10 or maybe 11?), pre-OLED, and webOS on it was version 3.0. Maybe situation has improved with newer models, I don't know. The problem with TVs, is that they really work for a long time just fine and I see no reason to change it ahead of other more needed upgrades. It doesn't fall to the ground like phones, there is no degrading battery or degrading rubber/textile parts, TVs are really robust. So it would have been nice if the software for such long living hardware was also supported accordingly and that buyers would be informed about that in advance and that was my expectation for webOS/LG originally - since it is in C++, uses modern and maintained QT framework, snappy and LG is a bigcorpo, I expected it to keep up. But nope :( .
Angostura 1 days ago [-]
I have mine attached to the internet, but it does take a good 30 minutes plus Googling to find out all the places that you have to turn stuff off.
tosti 1 days ago [-]
3 out of 4 OLED screens in my household suffer from burned pixels. It's the early 90s all over again with OLED.
account42 1 days ago [-]
How old are these and how often / how long are they turned on? My OLED TV is over two years old now without any issues even though it gets frequent usage.
tosti 1 days ago [-]
I don't buy a TV every 2 years, that's absurd. If I buy a TV, it better work for > 10 years.
account42 1 days ago [-]
You are attacking a straw man instead of answering the question.
tosti 1 days ago [-]
They were second hand, idk. They were already burned when they arrived. Suffices for me to say I don't have much confidence in OLED.
mlrtime 1 days ago [-]
I have 3 LG OLEDs of all different generation and they all still go great. It is by far the best tv you can get vs other manufacturers.
smcleod 1 days ago [-]
You know your phone is OLED right? I'm assuming you left a still image on without the inbuilt screen refresher enabled or something? I remember seeing that way back in the early OLED days but not on good TVs in the last 8~ years.
tosti 1 days ago [-]
Yes, that's what bothers me. OLED was the newfangled improved technology, but I'd rather hold out until something better becomes affordable.
And buy what? Smasnug? Sony? They're all uniquely shit.
sharperguy 1 days ago [-]
I would love it if I could disable bluetooth on the TV. I have never connected it to any network and its still blaring "HELLO SOMEONE NEARBY HAS AN LG TV" to the entire neighbourhood 24/7.
MiddleEndian 2 days ago [-]
My LG DualUp monitors (with no internet access) recently triggered some LG Adware Bullshit to install on my Windows laptop. So I'd say stop using LG anything (or Windows anything since they're voluntarily in on the scam too lol). If you want the 2560x2880, maybe buy the knock-off INNOCN vertical monitors.
I would probably have a DualUp by now if I could find one available anywhere: it's a very appealing form factor. I looked at the INNOCN site, but only see normal-looking monitors there; do you have a model name or any pointers I could search for?
MiddleEndian 18 hours ago [-]
I will say I have two DualUp monitors and they are my favorite monitors I ever had so I'm sad I can no longer recommend them. 2560x2880 is perfect for programming, researching, writing documents, graphics work, and so on.
The INNOCN knockoff is the INNOCN 28C1Q. Likely the same panel.
Press the button to turn off the power strip when you're not watching it.
The other solution for those who have a flat white wall (or are willing to install a projection screen) and which I used for years and years: use a dumb projector. There are plenty of perfectly fine dumb projectors and they're very cheap too (compared to the equivalent TV). This also made for the largest diagonal I ever had, in a huge living room, which was really great: basically turning the living room into a mini home theater. I painted the walls etc. accordingly, including a special paint for the white projection wall and black for the side and back walls. This was a better experience than any $$$ TV.
Sadly atm I can't use my projector for my wall ain't flat and I can't install a projection screen and I've got nowhere to put my projector: I could use a short-throw one but the place ain't mine and I'm not allowed to drill holes etc.
So atm it's... Pressing the button on the power strip that powers the LG TV. I know, I know: doesn't help much when the TV is on.
Next thing to do is separate all the junk devices (TV, smartphones [the ultimate spying device btw, much more than your TV], smartwatches, tables, etc.) from your proper stuff (e.g. your important PC running Linux/FreeBSD/etc.). I use different physical LANs (and a bridge/router) but VLANs would do too.
Many cheap home routers also by default offer at least a "guest" network: a perfect place the TV and your relatives' devices when they visit and want access. Set usage quota on the guest network too.
At some point all these devices shall use other networks than yours, so you'll be sorry out of luck anyway. But as long as they don't come with their own battery, pressing the button on the power-strip is some kind of giant low-cost "hack this" middle finger.
otikik 1 days ago [-]
Stop buying LG
gambiting 1 days ago [-]
The problem I have is....it just works. I'm tired of having to manage 50 different devices to let my son watch some Gabbys Dollhouse on the TV. Our LG CX is now 6 years old and it just works. I only need one remote for all the apps and sound, and I don't need to worry about another device. I've tried both Apple TV and Amazon Fire Stick, and both were (subjectively) worse experiences than just using the apps built into the TV. So.....in the interest of making my life feel less like an IT admin of my own house....I think I'll just use the built in apps and keep my TV connected to the internet.
BeetleB 23 hours ago [-]
> I'm tired of having to manage 50 different devices to let my son watch some Gabbys Dollhouse on the TV.
Other than the TV, most people really have only one device (Roku, AppleTV, etc). Why do you need so many?
> I only need one remote for all the apps and sound,
True with Roku.
gambiting 22 hours ago [-]
It's called a hyperbole. But I already have to babysit a NAS and a media server, and make sure the Playstation and Xbox are up to date and signed in, the last thing I want is another device just to watch netflix on.
>>True with Roku
Can the Roku remote change the input source on the TV?
BeetleB 22 hours ago [-]
> But I already have to babysit a NAS and a media server
Is the NAS TV related? Why do you need these? My media is all on my PC, and I don't consider maintaining that as part of my TV burden. I have to maintain it anyway.
And what maintenance do you need for the PS and XBox? You just turn it on when you use it, and let it auto-update.
> Can the Roku remote change the input source on the TV?
Fair point.
Normally, I change the source only once during a whole session, so I do that right in the beginning if I need to.
awllau 1 days ago [-]
What happens to the copies already installed?
Spur says these SDKs can keep running after the app is closed and only stop when the user deletes the app or opts out. LG says developers must remove them or have their apps suspended, but the article doesn’t say whether that disables existing installs. If it doesn’t, LG needs to tell affected users which apps to remove.
Does webOS have any way to kill an installed app remotely?
mastazi 1 days ago [-]
I am afraid that my dumb TV, which I've been holding onto for many years, might be on its last leg.
I remember seeing privacy guides for smart TVs over the years, does anyone know a place with up to date info?
Most 55inch monitors are now "smart" sadly, so are most "digital signage" products. So there is no longer a way to get a true dumb panel at least over 50 inch
EDIT I am in Australia, there might be products that are available elsewhere but cannot be bought/shipped here
qq66 1 days ago [-]
If you don't ever give your network credentials to the Smart TV you've closed off 99% of the attack surface.
Tor3 1 days ago [-]
From previous discussions there are apparently TVs which will connect to any open network nearby, if it can find one.
I got myself a normal, non-smart Philips 49" TV some ten years ago, it's good, but I don't expect to be able to find something similar anymore.
worldofmatthew 1 days ago [-]
Your smart TV would make you risk going to prison for theft? Just because its open does not mean permission to use.
Tor3 12 hours ago [-]
Huh? Open networks are open. You don't go to prison for that. Anyway, as the next comment said, there aren't many open networks anymore, though you'll still find some (see other comment)
inigyou 7 hours ago [-]
Walking into a random house's open door is still illegal.
Anyway, intent matters. This probably wouldn't be found criminal unless there was malicious intent.
kyriakos 1 days ago [-]
Who runs open WiFi networks in 2026?
Tor3 12 hours ago [-]
Way less than before, but, as an example, the supermarket very close to my home (in my home country - my other comment elsewhere is about our home in Japan) has an open network. It's presumably so that when customers are there then the supermarket's app, on customers phones, will have access to coupons and the like.
My own phone utilizes that (I don't use a data plan with that phone, as I mostly use it for calls and not having a data plan saves me a ton of money - it's basically free).
kyriakos 12 hours ago [-]
I've seen a lot of open networks in stores, cafes and malls in my country too but on most occasions they at least take you to a captive portal to accept their TOS or ask you to enter an email address to spam you later, they are not just connect and browse with zero interaction.
22 hours ago [-]
m132 1 days ago [-]
Hopefully nobody, but still—it takes just one
permo-w 1 days ago [-]
Japan is full of them
Tor3 12 hours ago [-]
I haven't seen that many actually. In our neighborhood in Japan the area is crowded with home networks, they're all encrypted.
And when I've tried navigating in large cities (Tokyo included) and found that my stupid tablet's GPS relied on getting the ephemeris data from the internet, and never through the GPS itself, I couldn't start navigating until I connected to something.. and I spent hours trying to find an open network, unsuccessfully. Happened twice, the second time in Nagoya. No open networks. Well, Starbucks have that, but then you need to find one.
kyriakos 1 days ago [-]
interesting. any idea why?
permo-w 1 days ago [-]
they say that Japan is simultaneously living 20 years in the past and 20 years in the future. lots of legacy devices are still being used for all manner of quirky convenience contraptions. they also live in an extremely high trust society where networks don't necessarily need to be secured
If you want a very specific example, the original nintendo DS can only connect to WEP connections, which meant that when I was there I was able to play parts of DS games that wouldn't have been accessible in the west
Don't connect your TV to the network. Use an external device for smart features like firestick, Apple tv, Google streamer etc (there are open source options too if you look around and don't mind missing some polish).
I have yet to receive a software update on any of my smart TVs that brought in any positive feature.
tikkabhuna 1 days ago [-]
I share your disappointment. I just want a screen with a tuner. If I want any “apps”, I’ll pair it with another device which will probably be an Apple TV.
I’m starting to wonder if a monitor and a soundbar with an external tuner is possible.
crote 1 days ago [-]
I don't even care about the tuner part. If I ever get the desire to watch linear TV again, I'll just get an IPTV subscription.
A decent-ish TV-sized panel with at least a single HDMI input really is all I need.
cynicalsecurity 1 days ago [-]
You can easily turn dumb mode on any smart TV.
JKCalhoun 1 days ago [-]
I helped a friend's mom set up a new TV she bought and was unable to get the TV to "come online" without 1) giving it network access and 2) setting up an account. Only then would the TV give access to the inputs.
dizhn 1 days ago [-]
In my country install service is included in the price (mounting a wall holder inclusive) and required for warranty service. They go yes,yes,yes to every question on the install steps it becomes a blur. Must be part of their training. You can always get a hospitality tv though. They are pretty dumb unless you go into secret menus and such to enable network features.
mancerayder 1 days ago [-]
Some have long splash screens and nag screens to punish those not on Wifi. TCL I believe was doing this, and I've read scattered reports of that behavior. Do research beforehand just in case.
lifeisstillgood 1 days ago [-]
Wait - how? I thought the whole reason the darn things are lower cost than equivalent PC monitors is the smart mode tracks viewing habits and seeks that to data brokers?
yodon 2 days ago [-]
If other non-Android-based TV manufacturers follow, this will have a much bigger impact on the spread (and cost) of scraping than either Anubis or Cloudflare.
akersten 2 days ago [-]
is this some kind of tactical distraction from the other LG headlines this week?
I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.
Marsymars 2 days ago [-]
> I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.
The platforms in question here are webOS and Tizen, neither of which are Android or use the Google Play Store.
ssl-3 2 days ago [-]
That only applies to the subset of TVs that use Google TV/Android TV.
Not so much for the rest of them that have operating systems with names like Roku TV OS, Tizen, WebOS, and Fire TV OS. They do their own things.
ranger_danger 2 days ago [-]
LG webOS is not Android though, it's from the old Palm/HP devices of the early 2010s. And I'm pretty sure there are still tons of play store apps with these proxy SDKs in them, advertised/consented or not.
ifh-hn 1 days ago [-]
My question is how would a user know their TV is being used like this?
Also this is the reason you down download random crap onto your devices.
I have an LG that is connected on its own network with bare minimal apps (netflix, prime, etc) because it's too convenient for my family. I actually bought it because it didn't display ads on the home screen like the other smart TVs I'd researched. Thought LG was the lesser evil, turns out they're all a bad as each other.
iso1631 1 days ago [-]
Only reason LG doesn't have adverts is by forcing it to use a pihole, but even that needs updating -- recently they've managed to push things through and I need to do another investigation to see what needs blocking. Trouble is I only see them when I'm not in the mood to be working, and then forget about them
regexorcist 1 days ago [-]
They hardcode DNS servers into the TV. You need a firewall in front of the pihole intercepting that traffic, I use OpenWrt.
piguin 1 days ago [-]
Given how cheap screens are, I'm puzzled as to why keeping a smart-ass TV is worth this effort?
regexorcist 1 days ago [-]
I have that setup for my home network regardless. And my TV is the original C1 OLED, nothing compared when I got it. I wouldn't buy LG today.
iso1631 1 days ago [-]
I nat all my dns traffic to the pihole, but looking at the logs my lg tv is using the dhcp provided ones.
Of course DOH would break that but I don't get the feeling it's bypassing it.
glimshe 2 days ago [-]
My TV doesn't know my router's wi-fi password.
declan_roberts 2 days ago [-]
My TV thinks it's January 1st 1970.
kazinator 2 days ago [-]
And so it thinks it is fairly new, then, and doesn't require any tubes replaced. Should that change, it will let you know.
charles_f 2 days ago [-]
My TV isn't even connected to power
tclancy 1 days ago [-]
Proper air gap, that.
mc3301 2 days ago [-]
Every time anything asks for a DOB or anything like that, I enter the earliest date their system allows. Been doing it for decades.
I guess that might make me more trackable?
ahartmetz 2 days ago [-]
At least you could get some interesting ads. Do you want to participate in a longevity study?
laughing_man 1 days ago [-]
Heh. Steam thinks I'm 126.
inigyou 7 hours ago [-]
Ouch. I wouldn't risk lying to Steam, given what it has the ability to delete.
walrus01 2 days ago [-]
I've said it before on HN a long time ago but I'll repeat myself, I have about a thousand times more confidence that Sony and/or Microsoft will keep their PS5 and Xbox operating systems secure and not crapped up with stuff like this, than I do that random TV manufacturers will not result in a cybersecurity or privacy disaster.
Yeah, the PS and Xbox OSes show you ads, and they have telemetry. But both companies also have an extremely important core functional need of keeping them secure, because possible fuckery with the OS could result in game piracy/DRM bypasses and a direct threat to their revenue models.
thewebguyd 2 days ago [-]
The gaming consoles aren't subsidized via the data collection like smart TVs are via content recognition (selling everything on your screen to advertisers).
Consoles are sometimes sold at a loss, but the revenue model is different. Playstation plus/game pass, a cut of game sales and microtransactions, exclusives, and accessories.
No one should ever connect their TV to the internet. There just isn't any reason to, get access to your streaming apps another way.
amazingman 2 days ago [-]
Hope you don't have any open WiFi networks nearby. IMO it's better to put it on one of your networks and isolate it from the internet and other devices.
tyre 2 days ago [-]
Yes. I bought a Samsung TV and there isn’t a way to set up Art Mode without the internet. So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.
What a wild experience 2026 is. But I do feel like a wizard.
walrus01 2 days ago [-]
You don't need an actual physical raspberry pi to temporarily run pihole on your LAN, you can, for instance, install a barebones debian VM inside any common hypervisor on your laptop like virtualbox or qemu, then install pihole on that basic debian x86-64 system.
2 days ago [-]
entropie 2 days ago [-]
They might hardcode DNS. It's not certain that this will work.
slau 2 days ago [-]
This is why I’m a bit conflicted about DoH and ODoH. Firefox and Chrome have defaulted to DoH for years if I’m not mistaken (although I’m in Europe so I believe my FF still uses regular DNS instead of DoH by default).
This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.
TeMPOraL 1 days ago [-]
That's why I'm not a fan of DoH or certificate pinning. Those are tools of control.
tkel 2 days ago [-]
I have my router set with iptables rules to block/redirect all port 53 and you can also add known DoH to a blocklist to try and force LAN devices to use your router DNS.
lodovic 2 days ago [-]
I have a separate lan for untrusted devices, I only use whitelisting. No public DNS for these devices.
tyre 15 hours ago [-]
You are correct! They do and it was bypassing my pihole. I was able to get around this but man they really want to stalk people.
CyberDildonics 2 days ago [-]
You can intercept normal DNS with iptables rules.
The best way to deal with a TV you don't trust is what no one wants to hear.
Open up the back and disconnect the wifi antenna. It is easy to open them up and everything is pretty simple and obvious once you do.
drnick1 2 days ago [-]
> Open up the back and disconnect the wifi antenna.
Upvoted. This is precisely the kind of thing I expect to read on HN.
CyberDildonics 1 days ago [-]
It's not even some difficult technical task like people think. The back of a TV is kind of like a PC but much simpler.
There is the power board (AC to DC conversion for electronics and leds), video input board (where you plug in HDMI etc) and a t-con board, which takes a single video signal in from the input board and drives the LCD screen.
Then there are a few ancillary components like speakers, maybe a roku module etc. There are easy to find and everything is modular. You can take the speakers out and use them somewhere else if you want. You can just disconnect the wifi antennae on the smart tv board and be done with it. You can also find the IR led connection that the remote sends signals to.
Jnr 1 days ago [-]
I block known DoH servers on my lan and forward all dns requests to my dns server.
drnick1 2 days ago [-]
> So first you have to get a raspberry pi, install pi hole, then switch your router’s DNS.
This does not provide any meaningful protection against data exfiltration. The TV is very possibly using public DNS or outright phoning home through stable IPs.
RiverCrochet 2 days ago [-]
I haven't seen any open WiFi networks around me in years. I don't think it's a thing anymore; it's definitely not something a TV company can rely on.
baby_souffle 2 days ago [-]
They're not unheard of in cities. Hotels and shopping malls have them. Some residential ISPs will also broadcast a public access point using a slice of each customer's bandwidth allocation...
When I had Comcast internet, I could get on those, but it required a network profile to actually connect to the internet. That said, I wouldn’t put it past TV makers and Comcast to collude on using this to allow backdoor network exfiltration.
RiverCrochet 1 days ago [-]
TV makers would have to collude with every ISP for that to be worth depending on.
Not to say it couldn't happen - but it wouldn't be a backdoor thing, it'd be very up front. All that's needed is for ISPs to create/join some SSO-like standard that lets you use ISP credentials as smart TV credentials (e.g. Your Xfinity account is automatically your Vizio account, sign on with your Xfinity account to get free streaming deals now).
I feel like if TVs start doing that, they'll display a network ID and signal bars at the top of the screen like cell phones do, so the TV maker doesn't get blamed for ISP problems.
prmoustache 2 days ago [-]
They all have captive portal for regulatory reasons though.
Symbiote 1 days ago [-]
Depends on the country.
The cafe I live above in Denmark just has an open network.
MrDrMcCoy 2 days ago [-]
If it connects to another network, it's somebody else's problem. Unless of course, it has a built in webcam or microphone.
stvltvs 2 days ago [-]
It does, at least for any media played through the device. Read up on automatic content recognition.
Its your problem if it updates itself to show ads (and of course exfiltrate whatever it can see / hear).
Hamuko 2 days ago [-]
I have an open guest network with a captive portal, and not once have I seen my LG TV try to connect to it.
gboss 2 days ago [-]
Pretty sure they can get internet through the HDMI cord from Roku or similar device
MrDrMcCoy 2 days ago [-]
Source? HDMI includes Ethernet in the spec, but I've never heard of any devices actually implementing it.
mikestew 2 days ago [-]
This again? Yes, it’s in the spec. No, no one has been shown to have actually implemented it. No streaming box is going to allow random devices to use their connection.
RiverCrochet 2 days ago [-]
That would require the Roku to specifically be set up to act as a router. You can't just connect to a random device that's not specifically a router/AP and use its internet connection.
Since Roku like other smart TV companies makes money off of user data captur, it's not incentivized to enable those conditions for a downstream device, especially if not specifically advertised as a feature.
toast0 2 days ago [-]
If this was a feature they wanted to provide, it would simplest to set the Roku up as a bridge. No dhcp, no nat, just a virtual switch. Roku devices run on Linux, if their HDMI chip supports Ethernet and that's plumbed to a Linux supported MAC (probably not), it might take an hour to build and test the feature. Longer if the wifi interface doesn't like being bridged (I've seen that on some openwrt devices).
There's esp-idf examples from espressif for doing bridging on an esp32 if you have one with a MAC and a PHY and/or spi mac+phy.
Or for wired ethernet, they could include a three port switch IC.
walrus01 2 days ago [-]
does a roku provide a dhcp server, issue a dhcp lease, do NAT and routing to things that are plugged into it over the 100M ethernet built into a current gen HDMI link?
toast0 2 days ago [-]
E-Arc uses the wires intended for Ethernet. Hook your Roku up to an earc port if you're seriously concerned about it.
aussieguy1234 2 days ago [-]
This is the best approach
sureshpaulchamy 3 hours ago [-]
I face a different issue on LG TV, Every time i turn off the Live Plus option, but it got enabled again on its own without being asked. no consent at all. Has anyone else seen this ?
SlightlyLeftPad 3 hours ago [-]
Yes. Mine isn’t even connected to the internet. It triggers rage when shortly thereafter a full screen page takes over during the final minutes of a world cup game telling me that I need to connect to the internet to use voice control. I watch using apple tv so that turns into a panic to find the lg remote I never use to skip this menu.
sureshpaulchamy 3 hours ago [-]
thats weird i thought of getting Apple tv will solve this issue, looks like it bring new issues
boomskats 6 hours ago [-]
Some of you might want to check out throwaway96/dejavuln-autoroot or the older throwaway96/faultmanager-autoroot, www.webosbrew.org/rooting and cani.rootmy.tv. Looks like it's patchy for the very latest models, but you might find the literature useful anyway.
ram_rattle 2 days ago [-]
Apparently all these vendors did nothing to prevent this, a nice article from spur intelligence
I'm very worried with all this bullshit around TVs.
I've been running the same Samsung UE40C6530 since 2010. It's 16 f'ng years and the thing works flawlessly like the first day. No other electronic device in my life worked so well, during so long.
But I'm about to move to a new home, and it feels like it's about time to get something more modern, at least a 4k TV.
But I'm honestly totally lost at what to buy. I do not want a "Smart" tv that's slow to start, bloated with crap, installing updates every day, and maybe even spying on me.
I want a plain, old, normal TV. If possible without Android or any advanced operating system. Just a TV. I'll plug external content myself, either via a Chromecast device, or something similar. I don't want my TV to be a full fledged computer.
Is there such a thing? What would you buy nowadays? It seems you're forced to get yet another computer to maintain and be worried about whatever you buy.
orly01 2 days ago [-]
I've heard you are not forced to connect to wifi, and on most of them you can connect make it default certain HDMI input. Latency to turn on/off might be less good than the 2010 one, but other than that this might be a very good way to do it.
geor9e 2 days ago [-]
If you hook an Apple TV (or similar) up to any 4k TV, and turn CEC on (to let the Apple TV control it), and never set it up otherwise, it becomes a dumb monitor.
dzhiurgis 1 days ago [-]
My parents got new telco IPTV boxes and they are excellent. Even voice search in our niche language works flawlessly.
Apple TV I got them few years ago just sits there unused.
Fantosism 2 days ago [-]
You buy a commercial panel used for advertising/signage that's 3x the price of the "Smart" consumer panels.
kaelwd 2 days ago [-]
Are there even any OLED commercial panels with HDR and VRR?
Fantosism 1 days ago [-]
Generally no, given that the expectation for commercial panels is to run 24/7.
thewebguyd 2 days ago [-]
the smart consumer panels would also be more expensive if they weren't subsidized via the spyware.
BeetleB 23 hours ago [-]
Same here. Same TV for the last 16 years. 1080p, but I'd rather keep it at that resolution than do the research and worry about smart TVs.
lwkl 1 days ago [-]
At least with Samsung TVs you can block them from accessing the internet after setting up the TV. Just use an Apple TV or Chromecast device after that.
Rubberducky1324 1 days ago [-]
I have an LG G5. I don't remember if I needed internet access to set it up, but currently I keep it offline and just use an Nvidia Shield (which is better anyway). No ACR, tracking, ads, ... in the TV itself.
By doing this you basically get a subsidized TV without paying with your data :D
jdmarble 2 days ago [-]
If you’re fine with “okay” picture quality, try a Sceptre. You can get them on Amazon. I’ve had good success with them. I heard you can still disable some smart features on Sony TVs.
unethical_ban 1 days ago [-]
My Sony tv has never connected to my network and it works great. I use an external device as the source.
dataengineer56 1 days ago [-]
The new Chromecasts and Apple TVs are really pretty good. I connect my LG TV to the wifi every few months to run updates, then disconnect it after. I control my TV through the Chromecast remote, so I never see any LG dashboards/apps.
Bud 2 days ago [-]
[dead]
kh2engab 2 days ago [-]
Is there a (technical) difference between a residential proxy and bot network node?
inigyou 7 hours ago [-]
Proxy is an application. Botnet is a delivery method. Residential is a classification that surveillance companies made up to stalk you better.
markasoftware 2 days ago [-]
Residential proxies operated by "legitimate" providers can only open TCP connections, which more or less rules out DDoS attacks, which seem to be the most common use of botnets. (And all tcp connections typically have to go through the proxy providers datacenter first to get through NAT, which effectively limits the total amount of traffic/connections you can make)
account42 1 days ago [-]
TCP only does NOT rule out DDoS, it just limits it to a subset of potentially less effective methods. All DDoS means is that you get a bunch of machines hammering a system.
Nursie 2 days ago [-]
A figleaf of "We gave ourselves permission on page 247, paragraph 3 of your user agreement"
charcircuit 1 days ago [-]
As they are both distributed systems there will be some inherit underlying similarities, but a botnet has things like antidebug, stealth, privilege escalation, etc. They typically include attack payloads or spying features like taking screenshots, keyloggers and stealing account information. Additionally they may include further ways of spreading to other computers such as messaging people on Discord or using other vulnerabilities. They might also try and take exclusive control of the device by patching security vulnerabilities and uninstalling other malware. Well unless they sell dropper capabilities letting other people deploy malware to the machine.
1 days ago [-]
jmward01 2 days ago [-]
Honestly I have nothing but anger for all parties involved here. We need to treat any appliance as hostile. Vote for people that will stop this stuff. Don't buy it. This is digital assault and should be treated as such.
If any of the HN crowd reading this are tech reviewers, make privacy and security a first class feature of the things you review. If it has a network connection then ask hard questions of the manufacturer about how they are managing that massive responsibility and what promises they have about how they will, and won't, use it. Ask what qualifies a 'trusted partner' and get a list of them so you can dig into them and report on how much those partners can or can't be trusted.
I really don't care how bright the screen is if this type of stuff happens. I'd rather watch nothing.
n1ivih 22 hours ago [-]
I have a Samsung odyssey ultrawide. All I want to do is have it display what I plug into the inputs. But I constantly have to approve new terms of service, install updates and worst of all switching inputs takes forever and often leads me to some tv guide like feature where I can stream a bunch of media.
Lg, Samsung… I mean are there any companies that make a non-smart monitor? This monitor I have was highly recommended on many review sites. Are we just accepting the fact that we don’t truly get to own or control these devices? It’s so frustrating.
TitaRusell 22 hours ago [-]
Ha yeah just last night I had Samsung television make me agree to some new terms. Its bloody annoying when you are watching Netflix. And ofcourse they actually want you to read it.
madhu_ghalame 11 hours ago [-]
Blocking residential proxy SDKs is the right decision. Smart TVs are meant for entertainment, not for routing third-party traffic. Security and user consent should always come before monetisation.
iugtmkbdfil834 2 days ago [-]
Heh. tinfoil hat on I always suspected that the AI gods would manifest themselves through TV. Hat stays on from this point on. It is not like LG suddenly found it in their heart to stop the money flow from the offending apps. Not when combined with recent security incident at frontier labs and current admin freaking out over open models.
lorreyfum 1 days ago [-]
LG is malware and spyware.
Utilera 1 days ago [-]
I can imagine someone choosing "no ads" without realizing they just agreed to let strangers route traffic through their home IP indefinitely
miki123211 1 days ago [-]
> researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.
Eh, so even sources as reliable as Krebs on Security sometimes engage in bad statistics.
This is a statistic that feels significant, but actually tells you nothing. For all we know, "42% of all apps" can mean a single spray-and-pray campaign with a few hundred downloads in total, with the vast majority of users only downloading apps from the top10, which are all unaffected. Or maybe the problem is widespread across the entire distribution of app downloads, with the majority of users having at least one infected app. We don't know either way, because "42% of apps" is a completely meaningless statistic.
gblargg 2 days ago [-]
So does this mean that using a proxy will cause all of the "smart" features to stop working? Win-win.
Farfignoggen 1 days ago [-]
"DO NOT BUY: LG’s Spyware TVs, Monitors, and Wiretapping Concerns
lg's had a good run of being a monitor, their software was a bit shit but the hardware supported e-arc etc.
i've got 2 expensive lg tvs and i bought them because you don't need to use their remote, it just turns on and shows the picture.
jbverschoor 2 days ago [-]
Thanks for the heads up, LG.
Those cheap/discount tv brands make soo much sense these days
atoav 1 days ago [-]
LG is on my blacklist. That means I won't buy LG products and in my job actively fight against buying products from them. And they put themselves onto that lost with their behavior.
is_true 1 days ago [-]
It's a shame because from the experience of people around me their appliances are some of the best, I mean for washing machines, fridges, etc.
xacky 1 days ago [-]
They should be banned from all app stores and added to anti virus definitions. Many smaller sites have already shutdown due to being DDOSed. Even Wikipedia gets attacked by them.
BrenBarn 2 days ago [-]
The messed up thing is that we need to rely on LG to stop allowing it rather than just making it illegal.
inigyou 7 hours ago [-]
Why would it be illegal though? What law?
jchw 2 days ago [-]
None of my TVs are connected to the Internet. That said, I could really do with a better open source fullscreen UI, especially since I mainly just want a web browser that works good. I'm just using KDE Plasma with a custom daemon to control the TV power state over an HDMI CEC adapter plus an old K830 keyboard.
I'm, frankly, a bit annoyed by this whole thing; I'd rather have USB adapter RF wireless because it is simpler to deal with vs Bluetooth, but actually I can't even find other Bluetooth keyboards that are as compelling as this K830 and worse yet, they don't even make the K830 anymore. I don't really mind KDE Plasma with just some minor customizations but I don't really like any of the options like Kodi. Maybe Plasma BigScreen will eventually be what I want for that. And finally, HDMI CEC is a pain in the ass. For reasons, I actually use an adapter to get CEC support on a normal PC platform, because most PC HDMI ports can't do it. And also, it's just a bizarre and overly complicated thing. I have it working reliably, but it took some time to iron out all the kinks, particularly because my TV responds quite differently depending on how recently it was powered off.
I really just want a big monitor and to basically just use DPMS... Like a computer does, but large computer monitors tend to be expensive and don't always have remote controls, which admittedly are handy.
account42 1 days ago [-]
Mind sharing what HDMI CEC adapter you use?
As for remote control - why would you want one for the monitor. For the PC I'm using an Air Mouse which is just a remote gyro-based mouse with keyboard buttons with a driverless USB dongle that acts like any other USB HID. I also have a miniature no-name wireless keyboard with a touchpad but rarely need to use it.
jchw 21 hours ago [-]
I am not home at the moment but I believe the setup I got working was the Club 3D CAC-1080 Display Port to HDMI adapter. The trick, as I understand it, is that these adapters support tunneling the CEC traffic to/from Display Port AUX, and many of the Linux DRM drivers support this. It has been a while since I actually set it up, but I don't remember it being particularly hard. I have a couple different adapters that theoretically support CEC I believe but that's the one I recall working.
> As for remote control - why would you want one for the monitor.
It certainly isn't strictly necessary, but it remains useful for input switching, and as a convenient backup option for power/volume. In the presence of a good fullscreen UI, I could see it being useful for basic directional input as well.
You can of course go the other way and handle input switching and all else via the PC, but that does mean if the PC isn't on nothing else works at all.
saint_yossarian 2 days ago [-]
K400+ user here, you might be interested in the upcoming Framework Wireless Touchpad Keyboard.
JoshTriplett 1 days ago [-]
> integrated touchpad that you don’t hate.
> no mouse buttons
Failed at the first sentence.
xnx 1 days ago [-]
I'm against undisclosed proxies, but I would pick pay-by-residential-proxy over pay-by-ads every time.
kittikitti 1 days ago [-]
An angle that's often not explored is that companies like BrightData that install spyware on your smart gadgets are based in Tel Aviv, Israel. It's not unreasonable to assume that these Israeli cybersecurity firms are also sending data to the Israeli military. While everyone is complaining about AI scrapers and bots, they aren't even looking at the main culprits.
1 days ago [-]
spudlyo 2 days ago [-]
One day there will be a decent TV that can be relatively easily hacked to run on open source firmware. My wife and I are moving soon, and I'm happy we've decided not to have a TV in the new place. Neither of our current LG TV's have ever been connected to the network, but it will feel good when I sell or give the cursed things away.
signalbright 1 days ago [-]
It's absolutely crazy that they were accepted in the first place
xena 2 days ago [-]
This is the best news I've heard all week. Finally good news for once!
br0ceph 6 hours ago [-]
2026, the year of the trojaned pacman app, lmfao
puck, man;
how are ppl so stupid
mancerayder 1 days ago [-]
After some research I went with a Sony Bravia. The screen is ridiculously reflective which is unusable next to any window at certain angles, and it wasn't the cheapest, but after some research since it uses that Google TV crap and has no splash screens, I could keep WiFi off on it and use my Apple TV.
TCL and now LG are to be fully avoided, Samsung isn't to be trusted (a future update if you allow it can lead to what happened here with LG). Samsung probably has the best hardware, but too bad.
If we don't vote with our wallets the enshittification of everything tech will march over and trample us that much faster.
gigel82 12 hours ago [-]
Because... they want to corner that market opportunity themselves at the system level? I doubt it'd be anything less given LG (and other smart TV manufacturers)'s track record.
BetterThanSober 2 days ago [-]
Stop buying "smart" TV
JoshTriplett 1 days ago [-]
I'd love to. Last I checked, nobody makes large-format high-quality tandem OLEDs that aren't smart TVs.
charcircuit 2 days ago [-]
>“The risk is amplified when consent comes from individuals within the household who use the device but shouldn’t give consent, such as minors.”
Note that the same applies for the other privacy invasive webos features. But since that doesn't harm big tech's monopoly they will conveniently avoid mentioning it.
beej71 1 days ago [-]
They just straight up ask people to be a proxy? And people say yes? SMH...
inigyou 7 hours ago [-]
Why wouldn't you? Better than ads.
beej71 5 hours ago [-]
I personally wouldn't because I don't want my IP associated with anything illegal.
inigyou 4 hours ago [-]
There are drug dealers right now shipping drug packages with your address as the return address. Does that bother you?
1 days ago [-]
symfoniq 2 days ago [-]
This is madness.
Only LG themselves should be able to have this kind of invasive control over your television.
pixl97 2 days ago [-]
I mean, why didn't they do that from the start?
steele 2 days ago [-]
Honeypot for more logos
sourav276 1 days ago [-]
[flagged]
jocelyner 2 days ago [-]
[dead]
aucisson_masque 1 days ago [-]
[dead]
cognitiveinline 2 days ago [-]
Sharing a slice of your internet in a privacy preserving way in exchange for something of value, seems fair, no?
walrus01 2 days ago [-]
Grey market residential proxy service providers are one of the most common methods of implementing bot spam, social media manipulation and plenty of straight-out fraud.
There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.
cognitiveinline 2 days ago [-]
You make a good point. I've reassessed and agree this is shady, and not a good pattern. And should be disabled/abolished.
hokumguru 2 days ago [-]
I mean, some of us have legitimate business needs to get past cloudflares frankly somewhat bs gatekeeping business model, however
walrus01 2 days ago [-]
Sure, I do as well, I have my own VPN into my home office that lets me run traffic outbound through its default gateway while I'm somewhere else. But letting random third parties I don't know run traffic through my house is another thing entirely.
mmakeev 1 days ago [-]
Do you really need residential ip for this? for my news scraping i have choose static datacenter proxy first, rotating only as fallback, direct as last. flaresolverr covered cloudflare js challenge, but it wedge on memory time to time, so i add healthcheck for it. on my own site aws waf meet datacenter ua with captcha, so i understand other side too. residential never was necessary for me, but maybe my targets are just easier, what do you scrape?
nikanj 1 days ago [-]
To be clear, bot spam and social media manipulation are legitimate business needs for the business selling said services.
JoshTriplett 1 days ago [-]
You can't have legitimate business needs if you're not a legitimate business in the first place. Ban them all.
charcircuit 2 days ago [-]
Just because others abuse privacy doesn't mean that we should remove privacy from everyone else. They also let you get around geoblocking.
nvme0n1p1 2 days ago [-]
You're free to let strangers download illegal images from a proxy running on your IP, but I sure as hell won't.
charcircuit 2 days ago [-]
If you don't want to share your internet with others, that is your choice, but please don't make seem like you are only sharing the internet with criminals. That is a harmful belief to spread.
ryandrake 2 days ago [-]
Only if the app provides 1. prominently-displayed, informed consent, 2. an option to opt-out without losing app functionality, or 3. joining the botnet provides some kind of actual benefit to the user, besides just money to the developer.
mirashii 2 days ago [-]
Add to that list respecting the TOS of the user's ISP so that the user does not get banned, and providing some sort of remuneration if illicit activity through the proxy causes problems for the primary user, and then _maybe_ you could call this all not shady as fuck.
ryandrake 2 days ago [-]
If only ISPs would actually crack down on (usually unwitting) users whose systems are participating in a malicious botnet or otherwise have their networks compromised. They could offer temporary disconnection + anti-malware support to get the user cleaned up, if they actually gave a shit.
walrus01 2 days ago [-]
No residential last mile broadband ISP at the scale of hundreds of thousands or millions of customers is presently willing to spend the salary/benefits/fully loaded employee cost on the massive teams of (somewhat technically clued in, not low wage) people it would take to effectively implement this.
account42 1 days ago [-]
They would be willing if they were themselves held liable for the illicit activity originating from their network otherwise.
justcool393 16 hours ago [-]
except we need ISPs to be treated as relatively neutral parties. we don't hold the water company liable if someone uses water to cook up meth
krackers 2 days ago [-]
Apparently at least one of the apps mentioned does that. From the article
>A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node.
ryandrake 2 days ago [-]
I wonder how informed the end user actually is, and if it's disclosed to them what kind of content might pass through their network as a result of agreeing.
charcircuit 2 days ago [-]
Most traffic is normal scraping like checking amazon prices.
account42 1 days ago [-]
There is really not good excuse to bundle this functionality with an unrelated app in the first place.
LoganDark 2 days ago [-]
Some residential proxy providers offer a few cents for the use of your network.
cognitiveinline 2 days ago [-]
No need of (2) and (3) - the user can choose to not install/use the app. (1) is the right fair boundary.
ryandrake 2 days ago [-]
Those apps just shouldn't exist.
I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"
Dylan16807 2 days ago [-]
Sometimes it's botnet, sometimes it's just accessing netflix without hitting big IP range bans.
If there are proxy apps that only do the latter sort of work than I'm actually in favor of them existing and being widespread.
xacky 1 days ago [-]
It is the same as when javascript was used to mine cryptocurrency before web browsers blocked it, exploiting other users computers for unfair gain.
account42 1 days ago [-]
Exactly. If there is a legitimate use case for sharing your connection it should be a separate apps users intentionally install.
NopIdoN 2 days ago [-]
"train our machine to identify traffic lights" or something
oasisbob 2 days ago [-]
No.
I'm surprised Comcast or some other ISP doesn't step in with a claim of tortious interference. Reselling or granting access to the ISPs services like this is almost always against the ISPs terms of service.
The consumer is in no place to consent to this exchange.
Dylan16807 2 days ago [-]
On the other hand if you want to resell 2% of your bandwidth the ISP shouldn't have any say in that.
ButlerianJihad 2 days ago [-]
Oh yes they can. If I'm a consumer, I pay for my connection that is sold to me and held in my name. I have no right to "resell" or "sublet" part of that. It is usually spelled out in the Terms of Service or Acceptable Use Policy.
At the very least, consumer connections explicitly disallow "Commercial Use". That means that you can't use them to run a business. You can't use them to turn a profit. You can't use them to generate revenue. That means no running servers, and that means no "reselling 2% of your bandwidth" for a few pennies because some Euro-Trash-Stranger wants to borrow it!
Dylan16807 2 days ago [-]
> At the very least, consumer connections explicitly disallow "Commercial Use".
And that's really bad! Far more than reselling, you should very much be able to run a website from home!
ButlerianJihad 2 days ago [-]
> And that's really bad!
No, it’s fair, and probably federally regulated.
You wanna run a business? Then get a business license, pay your business taxes, and sign up for a business Internet connection. That’s what they’re made for. Then run your servers to your heart’s content.
justcool393 15 hours ago [-]
so much of the early aughts small business and startups were people selling stuff and doing things out of ppls home. and not like the "startup industry" startups, actual startups
but aside from that, hosting a website or email server or newsgroup or game server with friends isnt necessarily hosting a business, not everything is a transactional relationship
TeMPOraL 1 days ago [-]
What if I don't want to run a business? I just want to run a website!
ButlerianJihad 12 hours ago [-]
Okay, I can understand that there are instances where people want to run a website or some kind of server, recreationally, or out-of-pocket, or cooperatively, outside of a business/corporate context.
But I'd say it's fundamentally a market segmentation. ISPs don't want consumers running servers on consumer connections. Think about it. This allows ISPs to plan deployments better. Consumers should be, well, consuming downloads and content rather than distributing it upstream. Therefore, for example, my DOCSIS connection is 10x downstream vs. upstream. And an ISP's consumer-level backbone can be planned much more effectively when consumers are consuming downloads.
If you wanna run a server then go colocate it, or run it as a legit business. You've got to accept some market segmentation here.
I purchased a new HP printer recently, and it's firmly a SOHO printer. Perhaps more powerful than I really needed. And guess what? I found out that it's not really supported by Chromebook or Android drivers. So... I've got to bounce all my print jobs through Linux! Ah well!
Dylan16807 8 hours ago [-]
Internet service should be as close to a dumb pipe as possible. It can be biased in one direction (though 10:1 is too much and future DOCSIS versions are remedying that) but even a slower upload can and should be able to do basic hosting.
account42 1 days ago [-]
We have this invention called money so that individuals don't need to wrangle complex swap trades and instead sell the things (usually their time) that they are OK with selling with informed consent and buy the things they want without having to give up things they don't want to or don't understand. If selling your internet connection was a reasonable thing to do there would be dedicated apps/boxes for that instead of this being packaged into random apps.
nullsanity 2 days ago [-]
[dead]
boredatoms 2 days ago [-]
Tell your relatives, buy an apple tv
amlib 2 days ago [-]
I don't think apple makes actual tvs
boredatoms 2 days ago [-]
Whats your point exactly? Are you purposely being obtuse?
Plenty of uninformed people let their tv on the network, they shouldn’t. A separate box should instead. Tell me I'm wrong?
mDyJzDPmBdG 1 days ago [-]
You are wrong. Just idea of having to use to remotes is unacceptable level of friction to most people. We should not hail separate device as excuse to allow this shitty behaviour by TV manufacturers.
I guess the lawmakers won't move a finger and we have wait for consumer network equipment manufacturers[1] to advertise build in pi-hole and ACR/TV ads blocking on firewall level.
[1] Let's just forget for a second they are famous for low quality software full of security bugs
Also, I bought an LG soundbar to go along with it. You would think they would work well together. The soundbar sounds fine, but the synchronization drifts over time. I've tried optical, LG's enhanced optical (allows you to control the volume) and HDMI eARC. In theory optical in PCM mode works better, but then you give up the volume control. Why should an end customer know about any of this? Lip sync is a simple problem to solve (timing pulses and code slipping will always work) and they have failed at it.
Also: their remote sucks (compared with Roku).
Anyway, so no respect for LG.
Would definitely not buy with my own money. I actually really like a lot of LG's other appliances (we have a washer, dryer, and dual ovens from them that are great), but for a TV, I just want a dumb screen that I can hook an HDMI cable to and run off a computer.
Look into Digital Signage displays. You pay a brickload more money but get (much) higher quality in return.
Not anymore. The last time I checked B&H they weren't very much more expensive than comparable "smart" televisions.
https://www.lg.com/uk/lge-terms/
> i. CONSENT REQUIREMENT: You acknowledge and agree that it is your sole responsibility to obtain all necessary consents from any third parties whose voices may be captured by the Product and to notify household members and guests that their voices may be captured and processed, in compliance with applicable wiretapping, eavesdropping, and privacy laws. If anyone does not consent, you should disable the microphone or voice features in the settings. LGE disclaims any liability for your failure to obtain such consent or provide such notification
Genuinely one of the most batshit insane things I've seen a company pull, their entire board should be liquidated along with their parents for failing to raise them.
My LG TV doesn't support Bluetooth, and it's only maybe eight years old.
Instead of simply connecting to Bluetooth headphones, you're supposed to put some LG app on your smart phone, then sync that via wifi with another app on the TV, then connect your smart phone to the headphones via Bluetooth.
Instead, I just watch less TV and will not purchase LG in the future.
(And let's stop pretending that "LG" stands for "Life's Good" like it says on the power-on splash screen. It means "Lucky Goldstar." If life was good, I'd be able to use Bluetooth headphones.)
I was put off buying one as, here in Blighty, all LG TV's come with a built in Amazon Alexa which if you don't enable it, nags you every time you turn on the TV (talk about doing the bare minimum to comply with the GDPR!).
Services can dramatically reduce abuse by blocking entire IP ranges based on country of origin, organization, or type (hosting providers). But a company can't block US residential IPs if it would also cut off many of their real customers.
The US government (probably the NSA) should be cracking down hard on US residential proxy networks. They're a genuine national security threat, actual data/identity loss of American citizens, act as infra for foreign covert influence campaigns, botnets used in hacking/DoS attacks, etc.
Major US ISPs (Comcast, AT&T) should detect clearly suspicious activity coming from customer IPs and warn them to scan their computers, check their TV apps, and find whatever is turning their internet into a proxy. It's very bad for the customers too (slows things down, gets their IP banned, etc)
Fix social media, and leave the consumers alone.
Also the firehose of spam will continue regardless of what you do on the consumer end.
Second, everybody screamed loudly when they were cracking down on file sharing traffic. You're saying spying on the citizens is ok when it's for this little reason over here, but not this one over there. It doesn't track.
Not to mention most ISP abuse mailboxes are automated these days because they are flooded with LLM-generated reports from "security" grifters.
The tech industry flooding the market with countless IoS (Internet of Shit) devices didn't help. This has moved way beyond accidentally installing spyware on your PC. People are intentionally bugging their homes with these devices.
I understand the FCC is trying to crack down on this stuff - starting with routers - but of course that gets pushback too. You can't win.
ISPs already deal with abuse reports like this, the system just isn't being operated comptently.
The US government should already be infiltrating hacker groups and identifying infected American computers. Internet providers should be informing customers that hackers have compromised their devices.
Characterizing this as "mutilating the internet" is ridiculous.
You actually think the actors that went to the trouble to surreptitiously set this infrastructure up are going to share it with everyone for free?
They are intentionally made hard to detect and access is sold to the highest bidder.
Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.
Okay, I was being imprecise. These residential proxies aren't "open proxies" in the traditional sense, but they're usually "open" to anyone willing to pay a small amount of money to use them.
> Most ISP abuse reports are routinely ignored. They might as well be a dead letter box.
This is where regulation might play a role, or at least a change in attitude. Companies shouldn't be allowed to pollute the internet in this way when they can easily prevent it.
Unless you are doing GFW China-level traffic analysis against a blacklist, which again how do you prove?
Why do you think that? These are proxies, so they're making huge numbers of outbound connections to websites on behalf of the people operating them. They are the "exit nodes" in this setup.
You could probably just count the number of unique destination IPs they connect to each day. If the average residential user connects to 5,000, an infected machine is probably connecting to 50,000+.
But the simplest approach is to buy access to these illicit proxy services and use them to make requests to web servers you control. If you see your own unique request arrive from a residential IP, you've proven that connection is being used as a proxy.
> But a company can't block US residential IPs if it would also cut off many of their real customers.
since when do companies care whether they cut off real customers? i've been paying for residential proxies for everyday internet browsing for nearly 6 months. because it's the only way to pass the captcha service of another famous company headquartered in San Francisco
Is there incentive for them to? If anything, you might be paying extra for the data use and not even know it, right? They would lose money
if someone wants to knowingly host a proxy they should. stuffing it along with other apps is shady and if LG wants to disallow those apps from their store than w/e but like we don't need governmental stuff encroaching on this stuff. if LG wants to do moderation on those apps than whatever.
there was a lot of fighting over this stuff back in the early 2010s because the alternative was effectively a balkanized corponet.
smart TVs, by virtue of being devices you can write apps for, have morphed into more general purpose computing devices and keeping it as open as it can be is important. the backsliding from stuff like Android has been horrible for the ecosystem and that shouldn't be normalized, let alone as a legal requirement geez
Even if no one goes to jail, the NSA could make residential proxies much harder to operate in the US simply by detecting them and reporting them to ISPs. It would be good for ISPs to then validate the reports properly, give warnings, etc.
- Malware that can record video and audio from infected devices.
- Infrastructure for foreign covert influence campaigns.
- Botnets used in hacking and DoS attacks.
Does having TLS everywhere make this much harder?
Back in the real world, you can also passively fingerprint TLS handshakes to characterise the client device. Most of these proxy networks masquerade as "normal" clients, but if the type and variety of device fingerprints for an IP suddenly changes, that's a signal too.
But then, by standards of two decades ago, every website that cannot legally avoid showing a GDPR popup would be classified as malware. As it should be today. Alas, standards have changed.
I don't think you've read GDPR. In Europe (at least my part), *every* organization has a GDPR policy you need to agree to. Your child's school. Summer camps. Etc. Most are also conservative and reasonable.
What's broken is the GDPR popup with a dozen "legitimate interest" toggles for spying on you.
1. https://en.wikipedia.org/wiki/Hola_(VPN)
To sue them you'd have to show some actual, concrete harm. For example you contact a site that is blocking you and they tell you it's due to a certain request and you trace that request to the proxy.
This won't change unless governments create and enforce laws.
A lack of enforcement actions has caused situations like this.
Why would LG do better when it's cheaper to not?
I have an LG TV, about 6 years old now. For a while it was connected to the internet. Every time I turned it on, after a ~20s delay, it would pop up asking me to install an update and I would press RIGHT + OK to select the "No" button because it worked fine and previous updates just made it slower, added ads etc.
Eventually, the remote dropped the button press for RIGHT, and just got the OK. Or maybe I just pressed the buttons too fast -- the interface is laggy and I'd developed muscle memory. This started the software update with no way to cancel from the UI. Once it updated, it made me accept a new EULA just to continue using the TV in the way I already used it (which was mostly as an HDMI display). There was no way to even get to the settings dialog to perform a factory reset without accepting the EULA. The device was held hostage until I said "Accept."
This is the level of consent implied by accepting the EULA on a TV: none. It's bullshit. Computers should never have been put in TVs, and a smart TV should never be connected to the internet.
What's the difference between running a Tor exit node and a "residential proxy" except optics?
Look: I'm 100% for banning secret proxies that hide from the user, but stopping people knowingly and voluntarily running these proxies is a violation of fundamental software freedom tenets.
Sure, in principle that’s true.
But in practice, is it really fair to expect everyone to understand the health risks of every possible ingredient?
Likewise here, is it fair to expect the average consumer to understand what it means to host a residential proxy? Or even what a residential proxy is?
The article is quite clear that LG runs an "app store" where 42% of the "apps" likely contain residential proxies, and LG is going to make its "app store" developers stop doing that. From TFA:
> “A residential proxy network is not an intended use for LG smart TVs, and LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform,” Taylor said. “If this option is not removed, these apps will be suspended.”
This says nothing about your own software installed on the TV, should that be possible.
But even if you ran your own software on your TV, would you run a proxy service? Given you already have a residential ISP, you wouldn't need to hook your TV up to a botnet and buy residental ISP access for your scrapers via your own, or other unwitting suckers', TVs.
Your hypothetical of wanting to run a Tor exit node is silly. Most Tor exit node operators run them knowingly on dedicated hardware, usually in a datacentre, not their own home, and prepare themselves legally for when they inevitably get emails from law enforcement, or worse, raided. You'd almost certainly firewall the destinations it can reach, you wouldn't let it have access to your own network, and you wouldn't run it on your TV.
There is certainly a conversation to be had regarding consumer protection laws, the nature of an appliance, and the trade-offs thereof but this is not that conversation and I don't think you engaged in good faith with the comment you replied to.
Read it again: "LG Electronics is working with developers to remove the residential proxy option from their apps on the webOS platform"
It is working with developers it has a contractual relationship with, and has approved their apps for download from its "app store" -- this one: https://gb.lgappstv.com/main/tvapp
...where 42% seem to be ADDING THE TV TO A BOTNET.
LG TVs form a substantial botnet, and LG didn't appear to know or care.
This is not about a person using their own TV to add it to a botnet (WHY WOULD THEY DO THAT?), it's about "app developers" knowing that LG is lax in checking what "apps" do, and putting out trojan horse apps that, if the TV user installs them, adds the TV to a botnet, without the TV owner's knowledge.
This is entirely orthogonal to "can I run my own choice of software on my LG TV?", which is not addressed in the article at all.
It takes one look at the App Store on these TV to know all these apps are sketchy...
I own an airgapped LG TV. Does anyone actually want to go class action/mass arb?
I looked into this last year while researching TVs and couldn’t find anything to substantiate it.
Probably. The LG TV I have doesn't have cellular, but does have a removeable Wifi/Bluetooth module [1]. You have to disconnect a ribbon, unscrew the module and then pop it out.
[1] https://www.manualslib.com/manual/3140596/Lg-Oled83g3-Series...
This seems a little like worrying about getting Dodo poisoning.
I have family who get frustrated with their home Wi-fi and about every other year conclude the solution is to unsecure the connection.
This is for a fucking TV.
Very unfortunate.
Glad my 2007 Sony Bravia still works, even if only standard HD.
Besides, there's no shortage of dumb phones and featurephones on the market. We want the same for TVs.
LG's behavior isn't fine, but their monitors don't install crapware on Linux.
It's Windows Update that's installing LG crapware upon seeing relevant hardware IDs. That's why the problem affected older monitors too - it's the update side that suddenly started to ship malware.
This is also a misrepresentation. Microsoft has provided LG with a certificate to sign its driver packages with, and allows LG to upload packages to Windows Update, which includes a feature to install sidecar applications. Now, the spirit of this feature is that any application is meant to provide genuine configuration functionality or some graphical front end to the driver's configuration knobs.
LG then abused that feature to provide adware. Now, there are millions of hardware vendors. One can't expect that every driver package submission from every vendor is thoroughly vetted every time, this is a matter of trust and respect.
Sometimes one actually wants the app that comes with the device, like AMD's and NVIDIA's configuration trays.
Even so, I fully expect that after this debacle MS will disable this stuff. There is precedent for this. Synaptics/ELAN/Alps touchpad tray applications largely disappeared after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs. Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
Why not? Microsoft isn't a struggling startup. They can afford to do just that.
And if you really can't act responsibly "at scale" then you shouldn't be allowed that scale.
Maybe not, but LG has violated this trust and should therefore be either fined or severely restricted by Microsoft. Banning will likely cause more problems than solutions, but they shouldn't get away with this.
Adware was a huge problem during the Windows XP era, can't believe it's coming back now through Microsoft's official channels.
Also I doubt there's actually millions of hardware vendors. But that aside, Microsoft has a duty to vet everything that they offer through their channels. If it's too expensive for them to do, do like Apple did and have those that want to make use of their distribution network (and trust) pay them.
> after MS implemented precision touchpads somewhere in 2015, and suddenly Windows touchpads became as precise as those on Macs.
There’s still a world of difference between a MacBook touchpad and a windows one. My work laptop (18 month old dell XPS) can’t hold a candle to my 6 year old MacBook’s trackpad.
> Likewise with RGB peripherals. Even GPU driver applications have increasingly become less useful as the most important features—power control, adaptive sync, HDR, etc have moved into native Windows settings.
The peripherals still need the addons though; I have ASUS armory crate, Corsair iCue and MSI center for my Motherboard, cooler and GPU respectively. They all suck.
The latest Dell trackpads are quite bad. Price or the product being premium or not unfortunately does not tell you if it will have a good trackpad or not. And it changes over time (Dell XPS used to have really good trackpads)
Basically you have to go to a store and try or find reviews that actually pay attention to this.
Oddly I've found otherwise (Dell Precision notebook from 2021, and Surface Laptop). It might be macOS's animations and smoothing interfering here, but I've found that my Windows touchpads are much more responsive, especially when swiping between desktops.
> The peripherals still need the addons though
Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.
> Ugh, this is annoying. Hardware vendors need to be banned from writing lousy, inefficient, unsafe software.
Yeah, I commented on the McAfee LG thread but the stuff that comes bundled with hardware is embarassing. I don’t know how Razer, Logitech, nvidia, MSI, asus, etc get away with it. The stuff is awful, even their “good” software. I work in games and a few years ago the biggest correlation we had between unexplained crashes/performance problems in the wild was users having MSI Afterburner installed. Users thought it did great things and fixed a bunch of games but it absolutely thrashed everything we worked very hard to do and caused no end of issues doing so.
Well, this is the whole market on its own. It's entrepreneurship. No different than every web SaaS startup trying to capture some entry-level piece of computer use and then constrain it so it interoperates only with their "net of trusted partners".
They get away with it because everyone is happy and making money - the users, notably, are not part of the group here, and have no voice. The users are resources to be exploited. Same as on the web, and on most markets these days.
Other overlay apps like discord https://www.reddit.com/r/discordapp/comments/1jncrlc/new_ove... have similar issues - the way they work is by drive hooks and drawing over the application; depending on how close you are to the limit and how the game loop is coded this can very easily (and often does) cause micro stuttering, and in cases like discord causes massive performance problems regularly.
My point here is simply that it's not the monitor that is installing this. Neither the malware nor the URLs to malware exist on the device - they get fetched as part of normal OS-side auto-provisioning, which is the part that was compromised.
They are downloading and installing something without the users consent.
It's nice to have drivers work without any intervention, same with "helper software" but along side the ease of use they also took on the responsibility.
If I download some random .exe from the net; I have to confirm that I want to run it, sometimes I even have to right click and unblock it to allow it to run, because it is "untrusted".
Their signature key, their auto-run system, everything done for ease of use means they own this.
Otherwise what does "trusted" mean?
And it's not like MS is too poor to do anything useful for their customers. They just don't want to unless the cost-benefit analysis pans out in their favor. The customer is worth as much as their wallet.
Isn't the debacle over? MS know about this by now. What's stopping them from killing it today?
A late resolution is barely a resolution at all. None of this functionality needs new Windows features.
If you're going to allow 3rd parties to install software on potentially billions of computers with far reaching privileges then you better have something in place other than 'just trust me bro'.
Hard to get worked up over "3rd parties" when even 1st parties cheerfully stomp all over the interests of their users. That ship sailed, caught fire, and sank to the bottom of the ocean the day Candy Crush appeared in the goddamned Start menu.
Self signing a driver should mean just that, not a driver, and a load of other things we feel like foisting on the user.
Half the reason I moved to Linux is because I just wanted to print something without getting a load of advertising from a printer company.
Apple seem to do a pretty decent job of just that
At least on Windows, the most you get is a scare screen saying 'this app is from an unidentified developer'. I know what I'd rather have.
Well that and side-loaded LG adware
Kinda agree but let's call it "misinformed" or something, instead of a lie.
Of course the details are important on some level. But that doesn't make everything else not matter and it doesn't turn an incomplete explanation into a lie.
This difference tells you that, for example, you cannot fix the problem by fixing the monitor, because the problem does not exist in hardware. It's actually entirely external to the hardware you own, because it exists entirely "in the cloud" (i.e. on MS and LG servers).
The hardware alone is not sufficient for this to happen, but if you were to modify or "fix" the monitor (specifically its firmware) so that it no longer identifies as an LG monitor, then it would no longer cause these ads to be shown.
In other words, if A causes B and B causes C then it is correct to say that A causes C.
The manufacturer implemented choices to deliberately install the software when the monitors are connected. The mechanism is not important to why this is outrageous.
1. Yes Windows must have "approved" the drivers
2. Windows Update runs automatically and not (usually) manually
3. Automatic update can't even be disabled, only manually postponed a bit
At least 2 and 3 are different on virtually every Linux distro. Also, I find it very unlikely that they would accept such behavior.
To give MS the benefit of the doubt here, now that this happened and has been reported on they might decide to enforce stricter rules on manufacturers in the future. But as a Windows user you don't have a choice in case you don't like how they decide and how their decisions might change again later.
This has an option to disable downloading of auxiliary apps when a device is connected. Yes, it's a Windows Update thing.
> Prevent Windows from auto-installing device companion apps, like LG Monitor App, Alienware Command Center and more.
Here's the thing it does: https://github.com/Raphire/Win11Debloat/blob/master/Regfiles...
What LG sent in for installation is not a simple .inf or .sys/.dll file. They sent in a whole bag of software which does all the nasty things, and Microsoft doesn't vet or care about the software installed as the "driver" of the hardware.
https://learn.microsoft.com/en-us/windows-hardware/drivers/i...
I guess that from Microsoft's perspective, the driver itself wasn't suspicious, but it installs a questionable sidecar app they would have never vetted anyway.
It's just a device attached to a computer.
But in a Plug-and-Play world, its addition is noticed by the operating system -- as has been normal for decades.
Microsoft's Windows operating system sees this new hardware ID and then goes forth to install whatever-the-fuck software it associates with that identification, presumably as a service to the user. (Did Microsoft approve it? Dunno. I'm just over hear eating popcorn.)
That's what I thought. It is vetted software, just like on Linux. Microsoft just doesn't care if it shows ads.
So something most desktop Linux users don't do.
It’s really only arch with the AUR and some others where completely untrusted packages are used. This is legitimately a better model than what windows does, although Microsoft has been trying to change this with winget.
I even used uname as a fuzzing tool, and that broke builds spectacularly. There's now a more reasonable uname in the sandbox for builds.
and no, this is not how most software is installed
https://rustup.rs/
anyone doing this should really take a very very big look in the mirror
Increasingly software is distributed by "curl dodgysite.com/get.sh|sudo bash -", no different to running "install.exe" on windows
Surely Windows Update is a vetted repo as much as arch or debian
Clearly the Linux model is more secure, and Microsoft knows it. It's a good idea for Microsoft to take inspiration here. It's only a matter of time before they do containerization too, ala Flatpak. The biggest hurdle to that is Windows doesn't have native containers and the entire container ecosystem is build around Linux.
If Microsoft wanted my advice, which they don't, I think it would cost less at this point to just make Windows a Linux distro. Wine is already better at running older Windows software than Windows. Just expand Wine a bit, add in acceleration where it doesn't already exist, and boom you're done. Nobody would even notice.
And maybe then Windows on ARM wouldn't suck so much.
Apps like Chrome and Spotify have been doing it for almost 20 years, since they made their Windows apps back in 2008. Python updated their installer to install to the user profile in 2015 with version 3.5.0. VSCode started doing it in 2018. Discord did it at launch in 2015. Zoom and Teams and Slack do it and have for a long time. Its been a pretty common pattern for a long time.
> Windows doesn't have native containers
Windows supports Windows containers natively and has supported Windows containers for a decade.
> maybe then Windows on ARM wouldn't suck so much.
Windows on Arm these days really isn't bad. It definitely sucked a lot several years ago with tons of compatibility issues (along the timeframe you said you last used it seriously), but they've made massive improvements since.
I don't think this is the norm at all. I have seen curl/bash install scripts for tools like Claude Code, but they don't use sudo, and the expectation is that you deploy them in isolated user accounts or containers.
Docker provides a convenience script at https://get.docker.com/ to install Docker into development environments non-interactively.
== Homebrew ==
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/inst...)"
Paste that in the macOS Terminal, a Linux shell or WSL. The script explains what it will do and then pauses before it does it. Read about other installation options.
== k3s ==
K3s provides an installation script that is a convenient way to install it as a service on systemd or openrc based systems. This script is available at https://get.k3s.io. To install K3s using this method, just run:
These scripts have lines like
> abort "Need sudo access on macOS (e.g. the user ${USER} needs to be an Administrator)!"
> # --- use sudo if we are not already root ---
Why are you lying right now? This is a norm across the dev tools world for businesses to distribute dodgy curl piped to bash scripts that users install without question, popular examples: homebrew, docker, nvm, bun, deno, k3s. There is zero "expectation" given by any of these install scripts that they are isolated. Can you even find a single source online that suggests doing what you said for you to think its a commonly held expectation?
The Linux approach has the downside of not having the drivers if a vendor has not been working with the kernel community before launch (or for those who haven't upgraded to a kernel that has the driver, e.g. a LTS release).
On the other hand, the driver is maintained by kernel developers, not created by the hardware developer who is not getting paid after they sell the device. This helps avoid abandoned / vulnerable drivers, or having the hardware dev search for... alternative revenue streams, as in this case.
Let's not diminish LG's part in all this.
Nobody is diminishing LG's blame, LG is guilty of installing malware, and Microsoft is guilty of being grossly negligent and facilitating it. Microsoft implemented this feature knowing that it would eventually be abused for something like this, and it's bad enough to be indistinguishable from malice.
I swear, OSs have become sports teams.
Linux's 'security model’ has plenty of holes. The very fact the kernel and much of its user-mode is written in C almost guarantees that its security model is worthless. The Linux ecosystem operates on trust and respect that can and has been easily abused by bad actors to provide supply-chain pwnage.
There have been so many zero-click local privilege escalation CVEs I've lost track.
Arch Linux AUR malware: https://lists.archlinux.org/archives/list/aur-general@lists....
You have confidence you are actually downloading the same foo as everyone else. And if there were an issue there would be pushback. Not so if you get some random exe from warez.com
Yes it isn't perfect, it's still a lot better than windows land.
Implementation bugs are not holes in the security model. Linux has plenty of those, as does Windows.
Windows security model trusts, downloads, and immediately executes arbitrary software when a new untrusted device is plugged in, without asking the user.
I guess with more and more consumer devices running Linux based OSes (SteamOS, Android, Bazzite, Silverblue, ..) that becomes more and more interesting.
And unfortunately the "I'm safe on my non-windows-system" argument doesn't count for long, as the 99% muggle crowd justifies a shift to a world where our non-certified (=> 'insecure') systems are not supported by big companies anymore, as it's currently happening on Android.
A tech YouTuber showing this off and all the anti consumer behavior. I’m assuming this threads article is for an LG PR piece trying to redirect anger at the app developers to hide the fact that they are engaged in the same behavior themselves.
No transcoding, no weird codec issues, just the raw files direct streamed from the underpowered Unraid box, into the back of the AVR where the audio is handled correctly and the video is sent to the screen.
But yeah external stick is much safer solution, then even tvs like TLC are a great brand.
You need to hook something up to a network, and another device would have similar risks.
Setting up a sandboxed VPC or auditing traffic is beyond the means of the average TV owner.
Do you think an Apple TV and a Walmart special TV have same risks? I don't. I give the Apple device my network credentials and the TV never sees them.
Another device might not give the free reign for all shitty malware like they do. Apple TV for one wouldn't.
No thanks, I prefer owning my media in a way that corporations can't just take it away whenever they feel like and where I can use (open source) players of my choosing.
But the replies are missing the point that most people aren't techies and won't go do this. They go to big box store, buy the tv, ask if it has netflix, done.
They won't (and shouldn't need to) install a ATV.
The consumer demand was/is for cheaper, and data mining is how OEMs got there. The general public got what they want, and OEMs got to keep their margins: "win-win".
It's the same thing with (US?) airlines: people wanted cheaper, and that's what was offered and they chose.
* https://www.samsung.com/us/business/displays/
Admittedly this doesn't stop the presumed screenshotting and microphone use and worse
- No Dolby Vision support, only HDR10+ - Issues with judder/micro stutter - History of nerfing TVs via OTA updates - HDMI ports randomly failing - Bad HDMI-CEC implementation - Selling completely different panel generations under the exact same model names.
That made a Samsung behave a little better. But giving it no network access is better.
Samsung is a complete mess, now charging $5/month to use smarthings with no local control. I'll never buy Samsung.
Android TV even has ads for Disney and Apple, which I never installed.
[1] https://github.com/spocky/miproja1
[2] https://github.com/mlm-games/flicky
We don't need treats this badly.
https://www.webosbrew.org/rooting/
https://old.reddit.com/r/pcmasterrace/comments/1v1pkbs/lg_sp... ← examples of others who ran into the same shit
The INNOCN knockoff is the INNOCN 28C1Q. Likely the same panel.
https://www.amazon.com/dp/B0BWDMYK83?peakEvent=4&dealEvent=1...
https://www.newegg.com/p/3D4-007R-00003
Out of stock on Amazon and Newegg
The other solution for those who have a flat white wall (or are willing to install a projection screen) and which I used for years and years: use a dumb projector. There are plenty of perfectly fine dumb projectors and they're very cheap too (compared to the equivalent TV). This also made for the largest diagonal I ever had, in a huge living room, which was really great: basically turning the living room into a mini home theater. I painted the walls etc. accordingly, including a special paint for the white projection wall and black for the side and back walls. This was a better experience than any $$$ TV.
Sadly atm I can't use my projector for my wall ain't flat and I can't install a projection screen and I've got nowhere to put my projector: I could use a short-throw one but the place ain't mine and I'm not allowed to drill holes etc.
So atm it's... Pressing the button on the power strip that powers the LG TV. I know, I know: doesn't help much when the TV is on.
Next thing to do is separate all the junk devices (TV, smartphones [the ultimate spying device btw, much more than your TV], smartwatches, tables, etc.) from your proper stuff (e.g. your important PC running Linux/FreeBSD/etc.). I use different physical LANs (and a bridge/router) but VLANs would do too.
Many cheap home routers also by default offer at least a "guest" network: a perfect place the TV and your relatives' devices when they visit and want access. Set usage quota on the guest network too.
At some point all these devices shall use other networks than yours, so you'll be sorry out of luck anyway. But as long as they don't come with their own battery, pressing the button on the power-strip is some kind of giant low-cost "hack this" middle finger.
Other than the TV, most people really have only one device (Roku, AppleTV, etc). Why do you need so many?
> I only need one remote for all the apps and sound,
True with Roku.
>>True with Roku
Can the Roku remote change the input source on the TV?
Is the NAS TV related? Why do you need these? My media is all on my PC, and I don't consider maintaining that as part of my TV burden. I have to maintain it anyway.
And what maintenance do you need for the PS and XBox? You just turn it on when you use it, and let it auto-update.
> Can the Roku remote change the input source on the TV?
Fair point.
Normally, I change the source only once during a whole session, so I do that right in the beginning if I need to.
Spur says these SDKs can keep running after the app is closed and only stop when the user deletes the app or opts out. LG says developers must remove them or have their apps suspended, but the article doesn’t say whether that disables existing installs. If it doesn’t, LG needs to tell affected users which apps to remove.
Does webOS have any way to kill an installed app remotely?
I remember seeing privacy guides for smart TVs over the years, does anyone know a place with up to date info?
Most 55inch monitors are now "smart" sadly, so are most "digital signage" products. So there is no longer a way to get a true dumb panel at least over 50 inch
EDIT I am in Australia, there might be products that are available elsewhere but cannot be bought/shipped here
I got myself a normal, non-smart Philips 49" TV some ten years ago, it's good, but I don't expect to be able to find something similar anymore.
Anyway, intent matters. This probably wouldn't be found criminal unless there was malicious intent.
And when I've tried navigating in large cities (Tokyo included) and found that my stupid tablet's GPS relied on getting the ephemeris data from the internet, and never through the GPS itself, I couldn't start navigating until I connected to something.. and I spent hours trying to find an open network, unsuccessfully. Happened twice, the second time in Nagoya. No open networks. Well, Starbucks have that, but then you need to find one.
If you want a very specific example, the original nintendo DS can only connect to WEP connections, which meant that when I was there I was able to play parts of DS games that wouldn't have been accessible in the west
I have yet to receive a software update on any of my smart TVs that brought in any positive feature.
I’m starting to wonder if a monitor and a soundbar with an external tuner is possible.
A decent-ish TV-sized panel with at least a single HDMI input really is all I need.
I thought residential proxies are already banned from SmartTV apps by virtue of practically every APK under the sun being subject to the Google Play terms of service.
The platforms in question here are webOS and Tizen, neither of which are Android or use the Google Play Store.
Not so much for the rest of them that have operating systems with names like Roku TV OS, Tizen, WebOS, and Fire TV OS. They do their own things.
Also this is the reason you down download random crap onto your devices.
I have an LG that is connected on its own network with bare minimal apps (netflix, prime, etc) because it's too convenient for my family. I actually bought it because it didn't display ads on the home screen like the other smart TVs I'd researched. Thought LG was the lesser evil, turns out they're all a bad as each other.
Of course DOH would break that but I don't get the feeling it's bypassing it.
I guess that might make me more trackable?
Yeah, the PS and Xbox OSes show you ads, and they have telemetry. But both companies also have an extremely important core functional need of keeping them secure, because possible fuckery with the OS could result in game piracy/DRM bypasses and a direct threat to their revenue models.
Consoles are sometimes sold at a loss, but the revenue model is different. Playstation plus/game pass, a cut of game sales and microtransactions, exclusives, and accessories.
No one should ever connect their TV to the internet. There just isn't any reason to, get access to your streaming apps another way.
What a wild experience 2026 is. But I do feel like a wizard.
This also means that DoH effectively sends all your queries to CloudFlare on FF. Chrome is slightly smarter and tries to map your DNS provider to a DoH implementation if known.
The best way to deal with a TV you don't trust is what no one wants to hear.
Open up the back and disconnect the wifi antenna. It is easy to open them up and everything is pretty simple and obvious once you do.
Upvoted. This is precisely the kind of thing I expect to read on HN.
There is the power board (AC to DC conversion for electronics and leds), video input board (where you plug in HDMI etc) and a t-con board, which takes a single video signal in from the input board and drives the LCD screen.
Then there are a few ancillary components like speakers, maybe a roku module etc. There are easy to find and everything is modular. You can take the speakers out and use them somewhere else if you want. You can just disconnect the wifi antennae on the smart tv board and be done with it. You can also find the IR led connection that the remote sends signals to.
This does not provide any meaningful protection against data exfiltration. The TV is very possibly using public DNS or outright phoning home through stable IPs.
Not to say it couldn't happen - but it wouldn't be a backdoor thing, it'd be very up front. All that's needed is for ISPs to create/join some SSO-like standard that lets you use ISP credentials as smart TV credentials (e.g. Your Xfinity account is automatically your Vizio account, sign on with your Xfinity account to get free streaming deals now).
I feel like if TVs start doing that, they'll display a network ID and signal bars at the top of the screen like cell phones do, so the TV maker doesn't get blamed for ISP problems.
The cafe I live above in Denmark just has an open network.
https://www.howtogeek.com/its-not-just-streaming-content-you...
Since Roku like other smart TV companies makes money off of user data captur, it's not incentivized to enable those conditions for a downstream device, especially if not specifically advertised as a feature.
There's esp-idf examples from espressif for doing bridging on an esp32 if you have one with a MAC and a PHY and/or spi mac+phy.
Or for wired ethernet, they could include a three port switch IC.
https://www.cbsnews.com/newyork/video/how-smart-tvs-may-be-s...
I've been running the same Samsung UE40C6530 since 2010. It's 16 f'ng years and the thing works flawlessly like the first day. No other electronic device in my life worked so well, during so long.
But I'm about to move to a new home, and it feels like it's about time to get something more modern, at least a 4k TV.
But I'm honestly totally lost at what to buy. I do not want a "Smart" tv that's slow to start, bloated with crap, installing updates every day, and maybe even spying on me.
I want a plain, old, normal TV. If possible without Android or any advanced operating system. Just a TV. I'll plug external content myself, either via a Chromecast device, or something similar. I don't want my TV to be a full fledged computer.
Is there such a thing? What would you buy nowadays? It seems you're forced to get yet another computer to maintain and be worried about whatever you buy.
Apple TV I got them few years ago just sits there unused.
By doing this you basically get a subsidized TV without paying with your data :D
If any of the HN crowd reading this are tech reviewers, make privacy and security a first class feature of the things you review. If it has a network connection then ask hard questions of the manufacturer about how they are managing that massive responsibility and what promises they have about how they will, and won't, use it. Ask what qualifies a 'trusted partner' and get a list of them so you can dig into them and report on how much those partners can or can't be trusted.
I really don't care how bright the screen is if this type of stuff happens. I'd rather watch nothing.
Lg, Samsung… I mean are there any companies that make a non-smart monitor? This monitor I have was highly recommended on many review sites. Are we just accepting the fact that we don’t truly get to own or control these devices? It’s so frustrating.
Eh, so even sources as reliable as Krebs on Security sometimes engage in bad statistics.
This is a statistic that feels significant, but actually tells you nothing. For all we know, "42% of all apps" can mean a single spray-and-pray campaign with a few hundred downloads in total, with the vast majority of users only downloading apps from the top10, which are all unaffected. Or maybe the problem is widespread across the entire distribution of app downloads, with the majority of users having at least one infected app. We don't know either way, because "42% of apps" is a completely meaningless statistic.
Gamers Nexus"
-
https://www.youtube.com/watch?v=Q9uefFYe6bM
i've got 2 expensive lg tvs and i bought them because you don't need to use their remote, it just turns on and shows the picture.
Those cheap/discount tv brands make soo much sense these days
I'm, frankly, a bit annoyed by this whole thing; I'd rather have USB adapter RF wireless because it is simpler to deal with vs Bluetooth, but actually I can't even find other Bluetooth keyboards that are as compelling as this K830 and worse yet, they don't even make the K830 anymore. I don't really mind KDE Plasma with just some minor customizations but I don't really like any of the options like Kodi. Maybe Plasma BigScreen will eventually be what I want for that. And finally, HDMI CEC is a pain in the ass. For reasons, I actually use an adapter to get CEC support on a normal PC platform, because most PC HDMI ports can't do it. And also, it's just a bizarre and overly complicated thing. I have it working reliably, but it took some time to iron out all the kinks, particularly because my TV responds quite differently depending on how recently it was powered off.
I really just want a big monitor and to basically just use DPMS... Like a computer does, but large computer monitors tend to be expensive and don't always have remote controls, which admittedly are handy.
As for remote control - why would you want one for the monitor. For the PC I'm using an Air Mouse which is just a remote gyro-based mouse with keyboard buttons with a driverless USB dongle that acts like any other USB HID. I also have a miniature no-name wireless keyboard with a touchpad but rarely need to use it.
> As for remote control - why would you want one for the monitor.
It certainly isn't strictly necessary, but it remains useful for input switching, and as a convenient backup option for power/volume. In the presence of a good fullscreen UI, I could see it being useful for basic directional input as well.
You can of course go the other way and handle input switching and all else via the PC, but that does mean if the PC isn't on nothing else works at all.
> no mouse buttons
Failed at the first sentence.
puck, man; how are ppl so stupid
TCL and now LG are to be fully avoided, Samsung isn't to be trusted (a future update if you allow it can lead to what happened here with LG). Samsung probably has the best hardware, but too bad.
If we don't vote with our wallets the enshittification of everything tech will march over and trample us that much faster.
Note that the same applies for the other privacy invasive webos features. But since that doesn't harm big tech's monopoly they will conveniently avoid mentioning it.
Only LG themselves should be able to have this kind of invasive control over your television.
There's all kinds of things that malicious actors want to do where they value coming from an ordinary (comcast, charter, centurylink, shaw cable, whatever) residential IP.
>A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node.
I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"
If there are proxy apps that only do the latter sort of work than I'm actually in favor of them existing and being widespread.
I'm surprised Comcast or some other ISP doesn't step in with a claim of tortious interference. Reselling or granting access to the ISPs services like this is almost always against the ISPs terms of service.
The consumer is in no place to consent to this exchange.
At the very least, consumer connections explicitly disallow "Commercial Use". That means that you can't use them to run a business. You can't use them to turn a profit. You can't use them to generate revenue. That means no running servers, and that means no "reselling 2% of your bandwidth" for a few pennies because some Euro-Trash-Stranger wants to borrow it!
And that's really bad! Far more than reselling, you should very much be able to run a website from home!
No, it’s fair, and probably federally regulated.
You wanna run a business? Then get a business license, pay your business taxes, and sign up for a business Internet connection. That’s what they’re made for. Then run your servers to your heart’s content.
but aside from that, hosting a website or email server or newsgroup or game server with friends isnt necessarily hosting a business, not everything is a transactional relationship
But I'd say it's fundamentally a market segmentation. ISPs don't want consumers running servers on consumer connections. Think about it. This allows ISPs to plan deployments better. Consumers should be, well, consuming downloads and content rather than distributing it upstream. Therefore, for example, my DOCSIS connection is 10x downstream vs. upstream. And an ISP's consumer-level backbone can be planned much more effectively when consumers are consuming downloads.
If you wanna run a server then go colocate it, or run it as a legit business. You've got to accept some market segmentation here.
I purchased a new HP printer recently, and it's firmly a SOHO printer. Perhaps more powerful than I really needed. And guess what? I found out that it's not really supported by Chromebook or Android drivers. So... I've got to bounce all my print jobs through Linux! Ah well!
Plenty of uninformed people let their tv on the network, they shouldn’t. A separate box should instead. Tell me I'm wrong?
[1] Let's just forget for a second they are famous for low quality software full of security bugs